| CVE-2024-28421 |
BDSA-2024-1534 |
Critical |
Mar 25, 2024 |
SQL Injection vulnerability in Razor 0.8.0 allows a remote attacker to escalate privileges via the ChannelModel::updateapk method of the channelmodle.p
more...
SQL Injection vulnerability in Razor 0.8.0 allows a remote attacker to escalate privileges via the ChannelModel::updateapk method of the channelmodle.php
less...
|
v0.8.0
|
| CVE-2022-36747 |
|
Medium |
Aug 30, 2022 |
Razor v0.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the function uploadchannel().
Razor v0.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the function uploadchannel().
less...
|
v0.8.0
|
| CVE-2019-10276 |
BDSA-2019-0878 |
Critical |
Mar 29, 2019 |
Western Bridge Cobub Razor 0.8.0 has a file upload vulnerability via the web/assets/swf/uploadify.php URI, as demonstrated by a .php file with the imag
more...
Western Bridge Cobub Razor 0.8.0 has a file upload vulnerability via the web/assets/swf/uploadify.php URI, as demonstrated by a .php file with the image/jpeg content type.
less...
|
v0.8.0
|
| CVE-2018-8770 |
BDSA-2018-1264 |
Medium |
Mar 18, 2018 |
Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via generate.php, controllers/getConfigTest.php, controllers/getUpdateTest.php, contro
more...
Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via generate.php, controllers/getConfigTest.php, controllers/getUpdateTest.php, controllers/postclientdataTest.php, controllers/posterrorTest.php, controllers/posteventTest.php, controllers/posttagTest.php, controllers/postusinglogTest.php, fixtures/Controller_fixt.php, fixtures/Controller_fixt2.php, fixtures/view_fixt2.php, libs/ipTest.php, or models/commonDbfix.php in tests/.
less...
|
v0.8.0
|
| CVE-2018-8057 |
BDSA-2018-1262 |
Critical |
Mar 11, 2018 |
A SQL Injection vulnerability exists in Western Bridge Cobub Razor 0.8.0 via the channel_name or platform parameter in a /index.php?/manage/channel/add
more...
A SQL Injection vulnerability exists in Western Bridge Cobub Razor 0.8.0 via the channel_name or platform parameter in a /index.php?/manage/channel/addchannel request, related to /application/controllers/manage/channel.php.
less...
|
v0.8.0
|
| CVE-2018-8056 |
|
High |
Mar 11, 2018 |
Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via an invalid channel_name parameter to /index.php?/manage/channel/addchannel or a di
more...
Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via an invalid channel_name parameter to /index.php?/manage/channel/addchannel or a direct request to /export.php.
less...
|
v0.8.0
|
| BDSA-2018-1044 |
|
Critical |
Apr 10, 2018 |
Cobub Razor contains cross-site request forgery (*CSRF*) and a stored cross-site scripting (*XSS*) vulnerabilities due improper input validation on use
more...
Cobub Razor contains cross-site request forgery (*CSRF*) and a stored cross-site scripting (*XSS*) vulnerabilities due improper input validation on user-supplied input and missing security checks such as a CSRF token. Using these vulnerabilities, an attacker could insert JavaScript code and steal an administrator's session cookies to craft other attacks.
less...
|
|