RSS   Vulnerabilities for 'USVN'   RSS

2020-12-31
 
CVE-2020-17363

CWE-78
 

 
USVN (aka User-friendly SVN) before 1.0.9 allows remote code execution via shell metacharacters in the number_start or number_end parameter to LastHundredRequest (aka lasthundredrequestAction) in the Timeline module. NOTE: this may overlap CVE-2020-25069.

 
2020-09-01
 
CVE-2020-25070

CWE-352
 

 
USVN (aka User-friendly SVN) before 1.0.10 allows CSRF, related to the lack of the SameSite Strict feature.

 
 
CVE-2020-25069

NVD-CWE-noinfo
 

 
USVN (aka User-friendly SVN) before 1.0.10 allows attackers to execute arbitrary code in the commit view.

 
2018-11-15
 
CVE-2018-0695

CWE-79
 

 
Cross-site scripting vulnerability in User-friendly SVN (USVN) Version 1.0.7 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

 
2007-11-13
 
CVE-2007-5945

 

 
USVN before 0.6.5 allows remote attackers to obtain a list of repository contents via unspecified vectors.

 

 >>> Vendor: USVN 2 Products
USVN
User-friendly svn


Copyright 2024, cxsecurity.com

 

Back to Top