cbcvebase.

Posh Project Posh vulnerabilities

4 known vulnerabilities affecting posh_project/posh.

Total CVEs
4
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2014-2211P3HIGHCVSS 7.5PoC≤ 3.2.1v3.0+7 more2014-03-03
CVE-2014-2211 [HIGH] CWE-89 CVE-2014-2211: SQL injection vulnerability in portal/addtoapplication.php in POSH (aka Posh portal or Portaneo) 3.0 SQL injection vulnerability in portal/addtoapplication.php in POSH (aka Posh portal or Portaneo) 3.0 before 3.3.0 allows remote attackers to execute arbitrary SQL commands via the rssurl parameter.
nvd
CVE-2014-2213P4MEDIUMCVSS 6.1≥ 3.0, ≤ 3.2.12019-11-22
CVE-2014-2213 [MEDIUM] CWE-601 CVE-2014-2213: Open redirect vulnerability in the password reset functionality in POSH 3.0 through 3.2.1 allows rem Open redirect vulnerability in the password reset functionality in POSH 3.0 through 3.2.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect parameter to portal/scr_sendmd5.php.
nvd
CVE-2014-2214P4MEDIUMCVSS 6.1≥ 3.0, ≤ 3.2.12019-11-22
CVE-2014-2214 [MEDIUM] CWE-79 CVE-2014-2214: Multiple cross-site scripting (XSS) vulnerabilities in POSH (aka Posh portal or Portaneo) 3.0 throug Multiple cross-site scripting (XSS) vulnerabilities in POSH (aka Posh portal or Portaneo) 3.0 through 3.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) error parameter to /includes/plugins/mobile/scripts/login.php or (2) id parameter to portal/openrssarticle.php
nvd
CVE-2014-2212P4MEDIUMCVSS 5.0≤ 3.3.0v1.0.1+22 more2014-04-01
CVE-2014-2212 [MEDIUM] CWE-255 CVE-2014-2212: The remember me feature in portal/scr_authentif.php in POSH (aka Posh portal or Portaneo) 3.0, 3.2.1 The remember me feature in portal/scr_authentif.php in POSH (aka Posh portal or Portaneo) 3.0, 3.2.1, 3.3.0, and earlier stores the username and MD5 digest of the password in cleartext in a cookie, which allows attackers to obtain sensitive information by reading this cookie.
nvd
Posh Project Posh vulnerabilities | cvebase