From 0a67191ff6f66ca09335632d7c58cab8b90fc3a8 Mon Sep 17 00:00:00 2001 From: feld Date: Thu, 16 Jul 2015 19:22:19 +0000 Subject: Document zenphoto vulnerabilities No CVE assigned yet --- security/vuxml/vuln.xml | 28 ++++++++++++++++++++++++++++ 1 file changed, 28 insertions(+) (limited to 'security') diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index 94e318c0a83f..7aec7b050edc 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -58,6 +58,34 @@ Notes: --> + + zenphoto -- multiple vulnerabilities + + + zenphoto + 1.4.9 + + + + +

zenphoto reports:

+
+

Fixes several SQL Injection, XSS and path traversal + security issues

+
+ +
+ + http://www.zenphoto.org/news/zenphoto-1.4.9 + http://seclists.org/oss-sec/2015/q3/123 + https://github.com/zenphoto/zenphoto/pull/935 + + + 2015-05-24 + 2015-07-16 + +
+ groovy -- remote execution of untrusted code -- cgit