Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
x2engine x2engine 4.1.7 vulnerabilities and exploits
(subscribe to this query)
668
VMScore
CVE-2014-5297
The actionSendErrorReport method in protected/controllers/SiteController.php in X2Engine 2.8 up to and including 4.1.7 allows remote malicious users to conduct PHP object injection and Server-Side Request Forgery (SSRF) attacks via crafted serialized data in the report parameter.
X2engine X2engine 4.1.7
X2engine X2engine 2.8
445
VMScore
CVE-2014-5298
FileUploadsFilter.php in X2Engine 4.1.7 and previous versions, when running on case-insensitive file systems, allows remote malicious users to bypass the upload blacklist and conduct unrestricted file upload attacks by uploading a file with an executable extension that contains u...
X2engine X2engine
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-32886
insecure direct object reference
CVE-2024-34342
file inclusion
CVE-2024-34562
CVE-2024-34347
CVE-2024-26026
CVE-2024-4647
unprivileged
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started