All CVEs — page 39 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
Allows an attacker to upload a web shell, gaining remote code execution capabilities on the web server.
This flaw allows unauthenticated attackers to execute arbitrary code by deserializing attacker-controlled bytes through the XML-RPC endpoint in Apache Roller 6.1.5, leading to remote code execution.
This flaw allows unauthenticated attackers to bind an outstanding request token to an arbitrary user account, including administrators, by submitting an unsigned authorization request. This can lead to unauthorized access and control over sensitive user accounts.
The flaw allows an authenticated user to read, modify, or delete content from other weblogs via the XML-RPC APIs, due to missing permission checks. This is critical as it can lead to unauthorized access and data manipulation.