Vulnerabilities (CVE)

Filtered by vendor Walrus Digit Subscribe
Filtered by product Walrack
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2011-1329 1 Walrus Digit 1 Walrack 2024-02-28 6.8 MEDIUM N/A
WalRack 1.x before 1.1.9 and 2.x before 2.0.7 does not properly restrict file uploads, which allows remote attackers to execute arbitrary PHP code via vectors involving a double extension, as demonstrated by a .php.zzz file.
CVE-2011-2215 1 Walrus Digit 1 Walrack 2024-02-28 7.5 HIGH N/A
Unspecified vulnerability in WalRack 1.x before 1.1.8 and 2.x before 2.0.6 has unknown impact and attack vectors, possibly related to file deletion and an encoded URL, a different vulnerability than CVE-2011-1329.