Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
4.9
CVE-2015-4425
- EPSS 3.81%
- Veröffentlicht 18.08.2015 17:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
Directory traversal vulnerability in pimcore before build 3473 allows remote authenticated users with the "assets" permission to create or write to arbitrary files via a .. (dot dot) in the dir parameter to admin/asset/add-asset-compatibility.
7.5
CVE-2014-2921
- EPSS 7.32%
- Veröffentlicht 21.04.2014 22:55:08
- Zuletzt bearbeitet 06.05.2026 22:30:45
The getObjectByToken function in Newsletter.php in the Pimcore_Tool_Newsletter module in pimcore 1.4.9 through 2.0.0 does not properly handle an object obtained by unserializing Lucene search data, which allows remote attackers to conduct PHP object ...
6.4
CVE-2014-2922
- EPSS 2.92%
- Veröffentlicht 21.04.2014 22:55:08
- Zuletzt bearbeitet 06.05.2026 22:30:45
The getObjectByToken function in Newsletter.php in the Pimcore_Tool_Newsletter module in pimcore 1.4.9 through 2.1.0 does not properly handle an object obtained by unserializing a pathname, which allows remote attackers to conduct PHP object injectio...