RSS   Vulnerabilities for 'Plex media server'   RSS

2019-11-18
 
CVE-2018-21031

CWE-522
 

 
Tautulli versions 2.1.38 and below allows remote attackers to bypass intended access control in Plex Media Server because the X-Plex-Token is mishandled and can be retrieved from Tautulli. NOTE: Initially, this id was associated with Plex Media Server 1.18.2.2029-36236cc4c as the affected product and version. Further research indicated that Tautulli is the correct affected product.

 
2014-12-07
 
CVE-2014-9304

 

 
Plex Media Server before 0.9.9.3 allows remote attackers to bypass the web server whitelist, conduct SSRF attacks, and execute arbitrary administrative actions via multiple crafted X-Plex-Url headers to system/proxy, which are inconsistently processed by the request handler in the backend web server.

 
2014-12-02
 
CVE-2014-9181

CWE-22
 

 
Multiple directory traversal vulnerabilities in Plex Media Server before 0.9.9.3 allow remote attackers to read arbitrary files via a .. (dot dot) in the URI to (1) manage/ or (2) web/ or remote authenticated users to read arbitrary files via a .. (dot dot) in the URI to resources/.

 

 >>> Vendor: PLEX 2 Products
Media server
Plex media server


Copyright 2024, cxsecurity.com

 

Back to Top