RSS   Vulnerabilities for 'Web-dorado spider video player'   RSS

2015-06-15
 
CVE-2015-4352

 

 
Cross-site request forgery (CSRF) vulnerability in the Spider Video Player module for Drupal allows remote attackers to hijack the authentication of administrators for requests that delete videos via unspecified vectors.

 
 
CVE-2015-4351

 

 
The Spider Video Player module for Drupal allows remote authenticated users with the "access Spider Video Player administration" permission to delete arbitrary files via a crafted URL.

 

 >>> Vendor: Web-dorado 14 Products
Photo gallery
Web-dorado spider video player
Spider facebook
Spider calendar
Ecommerce wd
Spider catalog
Spider event calendar
Event calendar wd
Contact form maker
Gallery wd
Form maker
Wp form builder
Backup-wd
Spidercatalog


Copyright 2024, cxsecurity.com

 

Back to Top