Kozos / Easyctf
3 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2015-0914 | EasyCTF before 1.4 does not validate the session ID, which allows remote attackers to obtain access via a crafted HTTP request. | MEDIUM | 5.0 | May 1, 2015 |
| CVE-2015-0913 | Cross-site scripting (XSS) vulnerability in EasyCTF before 1.4 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | LOW | 3.5 | May 1, 2015 |
| CVE-2015-0912 | EasyCTF before 1.4 allows remote authenticated users to write executable content to files via unspecified vectors. | MEDIUM | 6.5 | May 1, 2015 |
Showing 1 to 3 of 3 CVEs