Pydio

Pydio

20 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.53%
  • Published 31.05.2019 22:29:01
  • Last modified 21.11.2024 04:18:16

An unauthenticated attacker can obtain information about the Pydio 8.2.2 configuration including session timeout, libraries, and license information.

Exploit
  • EPSS 0.19%
  • Published 31.05.2019 22:29:00
  • Last modified 21.11.2024 04:18:16

The "action" get_sess_id in the web application of Pydio through 8.2.2 discloses the session cookie value in the response body, enabling scripts to get access to its value. This identifier can be reused by an attacker to impersonate a user and perfor...

Exploit
  • EPSS 9.39%
  • Published 15.01.2019 16:29:00
  • Last modified 21.11.2024 04:02:01

In Pydio before 8.2.2, an attack is possible via PHP Object Injection because a user is allowed to use the $phpserial$a:0:{} syntax to store a preference. An attacker either needs a "public link" of a file, or access to any unprivileged user account ...

  • EPSS 33.82%
  • Published 16.10.2018 22:29:01
  • Last modified 21.11.2024 03:49:45

Pydio 4.2.1 through 8.2.1 has an authenticated remote code execution vulnerability in which an attacker with administrator access to the web application can execute arbitrary code on the underlying system via Command Injection.

Exploit
  • EPSS 2.82%
  • Published 23.07.2018 15:29:00
  • Last modified 21.11.2024 03:57:03

Pydio version 8.2.1 and prior contains an Unvalidated user input leading to Remote Code Execution (RCE) vulnerability in plugins/action.antivirus/AntivirusScanner.php: Line 124, scanNow($nodeObject) that can result in An attacker gaining admin access...

Exploit
  • EPSS 0.35%
  • Published 23.07.2018 15:29:00
  • Last modified 21.11.2024 03:57:03

Pydio version 8.2.0 and earlier contains a Server-Side Request Forgery (SSRF) vulnerability in plugins/action.updater/UpgradeManager.php Line: 154, getUpgradePath($url) that can result in an authenticated admin users requesting arbitrary URL's, pivot...

Exploit
  • EPSS 0.19%
  • Published 23.07.2018 15:29:00
  • Last modified 21.11.2024 03:57:03

Pydio version 8.2.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in ./core/vendor/meenie/javascript-packer/example-inline.php line 48; ./core/vendor/dapphp/securimage/examples/test.mysql.static.php lines: 114,118 that can result in...

  • EPSS 0.23%
  • Published 19.09.2017 15:29:00
  • Last modified 20.04.2025 01:37:25

Multiple cross-site scripting (XSS) vulnerabilities in Pydio (formerly AjaXplorer) before 6.0.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Pydio XSS Vulnerabilities."

  • EPSS 6.18%
  • Published 19.09.2017 15:29:00
  • Last modified 20.04.2025 01:37:25

Pydio (formerly AjaXplorer) before 6.0.7 allows remote attackers to execute arbitrary commands via unspecified vectors, aka "Pydio OS Command Injection Vulnerabilities."

  • EPSS 9.5%
  • Published 27.12.2014 18:59:04
  • Last modified 12.04.2025 10:46:40

Unrestricted file upload vulnerability in plugins/editor.zoho/agent/save_zoho.php in the Zoho plugin in Pydio (formerly AjaXplorer) before 5.0.4 allows remote attackers to execute arbitrary code by uploading an executable file, and then accessing thi...