CVE Browser

More filters (active)
CVE-2021-47899 MEDIUM

YetiShare File Hosting Script 5.1.0 Remote File Upload SSRF Vulnerability

CVSS 6.9 EPSS 0.29% Jan 23, 2026
CVE-2019-20060 HIGH

MFScripts YetiShare v3.5.2 through v4.5.4 places sensitive information in the Referer header. If this leaks, then third parties may discover password-reset has…

CVSS 7.5 EPSS 1.45% Feb 10, 2020
CVE-2019-20061 HIGH

The user-introduction email in MFScripts YetiShare v3.5.2 through v4.5.4 may leak the (system-picked) password if this email is sent in cleartext. In other wor…

CVSS 7.5 EPSS 0.90% Feb 10, 2020
CVE-2019-20062 CRITICAL

MFScripts YetiShare v3.5.2 through v4.5.4 might allow an attacker to reset a password by using a leaked hash (the hash never expires until used).

CVSS 9.8 EPSS 1.57% Feb 10, 2020
CVE-2019-20059 HIGH

payment_manage.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.4 directly insert values from the sSortDir_0 parameter into a SQ…

CVSS 8.8 EPSS 0.94% Feb 10, 2020
CVE-2019-19806 MEDIUM

_account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 displays a message indicating whether an email address is configured for the accou…

CVSS 5.3 EPSS 0.99% Dec 30, 2019
CVE-2019-19805 MEDIUM

_account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 takes a different amount of time to return depending on whether an email address i…

CVSS 5.3 EPSS 0.99% Dec 30, 2019
CVE-2019-19738 MEDIUM

log_file_viewer.php in MFScripts YetiShare 3.5.2 through 4.5.3 does not sanitize or encode the output from the lFile parameter on the page, which would allow a…

CVSS 6.1 EPSS 0.71% Dec 30, 2019
CVE-2019-19737 HIGH

MFScripts YetiShare 3.5.2 through 4.5.3 does not set the SameSite flag on session cookies, allowing the cookie to be sent in cross-site requests and potentiall…

CVSS 8.8 EPSS 0.46% Dec 30, 2019
CVE-2019-19736 MEDIUM

MFScripts YetiShare 3.5.2 through 4.5.3 does not set the HttpOnly flag on session cookies, allowing the cookie to be read by script, which can potentially be u…

CVSS 6.1 EPSS 0.61% Dec 30, 2019
CVE-2019-19735 CRITICAL

class.userpeer.php in MFScripts YetiShare 3.5.2 through 4.5.3 uses an insecure method of creating password reset hashes (based only on microtime), which allows…

CVSS 9.1 EPSS 0.77% Dec 30, 2019
CVE-2019-19734 HIGH

_account_move_file_in_folder.ajax.php in MFScripts YetiShare 3.5.2 directly inserts values from the fileIds parameter into a SQL string. This allows an attacke…

CVSS 8.8 EPSS 1.11% Dec 30, 2019
CVE-2019-19733 MEDIUM

_get_all_file_server_paths.ajax.php (aka get_all_file_server_paths.ajax.php) in MFScripts YetiShare 3.5.2 through 4.5.3 does not sanitize or encode the output…

CVSS 6.1 EPSS 0.71% Dec 30, 2019
CVE-2019-19732 HIGH

translation_manage_text.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 directly insert values from the aSortDir_0 and/or sSo…

CVSS 7.2 EPSS 1.09% Dec 30, 2019
CVE-2019-19739 HIGH

MFScripts YetiShare 3.5.2 through 4.5.3 does not set the Secure flag on session cookies, allowing the cookie to be sent over cleartext channels.

CVSS 7.5 EPSS 0.67% Dec 30, 2019

Showing 1 to 15 CVEs · page 1