Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
roller vulnerabilities and exploits
(subscribe to this query)
755
VMScore
CVE-2014-0030
The XML-RPC protocol support in Apache Roller prior to 5.0.3 allows malicious users to conduct XML External Entity (XXE) attacks via unspecified vectors.
Apache Roller 4.0.1
Apache Roller 3.1
Apache Roller 4.0
Apache Roller 5.0
Apache Roller 5.0.1
Apache Roller 5.0.2
1 EDB exploit
685
VMScore
CVE-2013-4212
Certain getText methods in the ActionSupport controller in Apache Roller prior to 5.0.2 allow remote malicious users to execute arbitrary OGNL expressions via the first or second parameter, as demonstrated by the pageTitle parameter in the !getPageTitle sub-URL to roller-ui/login...
Apache Roller 4.0
Apache Roller 4.0.1
Apache Roller
Apache Roller 5.0
1 EDB exploit
1 Github repository
668
VMScore
CVE-2018-17198
Server-side Request Forgery (SSRF) and File Enumeration vulnerability in Apache Roller 5.2.1, 5.2.0 and previous versions unsupported versions relies on Java SAX Parser to implement its XML-RPC interface and by default that parser supports external entities in XML DOCTYPE, which ...
Apache Roller 5.2.1
Apache Roller
Apache Roller 5.2.0
605
VMScore
CVE-2012-2380
Multiple cross-site request forgery (CSRF) vulnerabilities in the admin/editor console in Apache Roller prior to 5.0.1 allow remote malicious users to hijack the authentication of admins or editors by leveraging the HTTP POST functionality.
Apache Roller
Apache Roller 2.3
Apache Roller 1.1.1
Apache Roller 1.1
Apache Roller 1.0.1
Apache Roller 1.0
Apache Roller 2.1.1
Apache Roller 2.0.2
Apache Roller 2.0.1
Apache Roller 2.1
Apache Roller 0.9.8.1
Apache Roller 0.9.7.2
Apache Roller 0.9.7.1
Apache Roller 0.9.7
Apache Roller 3.1
Apache Roller 4.0.1
Apache Roller 2.0
Apache Roller 1.2
Apache Roller 0.9.9
Apache Roller 0.9.6.3
Apache Roller 0.9.5
Apache Roller 4.0
578
VMScore
CVE-2015-0249
The weblog page template in Apache Roller 5.1 up to and including 5.1.1 allows remote authenticated users with admin privileges for a weblog to execute arbitrary Java code via crafted Velocity Text Language (aka VTL).
Apache Roller 5.1.0
Apache Roller 5.1.1
481
VMScore
CVE-2014-7802
The Top Roller Coasters Europe 2 (aka com.appaapps.top10tallesteuropeanrollercoasters2) application @7F050001 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle malicious users to spoof servers and obtain sensitive information via a cr...
Appa-apps Top Roller Coasters Europe 2 \\@7f050001
481
VMScore
CVE-2014-7087
The Top Roller Coasters Europe 1 (aka com.appaapps.top10tallesteuropeanrollercoasters1) application @7F050001 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle malicious users to spoof servers and obtain sensitive information via a cr...
Appa-apps Top Roller Coasters Europe 1 \\@7f050001
445
VMScore
CVE-2013-4668
Directory traversal vulnerability in File Roller 3.6.x prior to 3.6.4, 3.8.x prior to 3.8.3, and 3.9.x prior to 3.9.3, when libarchive is used, allows remote malicious users to create arbitrary files via a crafted archive that is not properly handled in a "Keep directory str...
File Roller Project File Roller
Canonical Ubuntu Linux 12.10
Canonical Ubuntu Linux 13.04
384
VMScore
CVE-2019-0234
A Reflected Cross-site Scripting (XSS) vulnerability exists in Apache Roller. Roller's Math Comment Authenticator did not property sanitize user input and could be exploited to perform Reflected Cross Site Scripting (XSS). The mitigation for this vulnerability is to upgrade ...
Apache Roller 5.2.1
Apache Roller 5.2.0
Apache Roller 5.2.2
383
VMScore
CVE-2021-33580
User controlled `request.getHeader("Referer")`, `request.getRequestURL()` and `request.getQueryString()` are used to build and run a regex expression. The attacker doesn't have to use a browser and may send a specially crafted Referer header programmatically. Since...
Apache Roller
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
privilege escalation
CVE-2024-20696
CVE-2024-29829
CVE-2024-33999
CVE-2024-35646
physical
CVE-2024-24919
CVE-2024-31030
local users
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »