📦

apache2triad

Vendor: apache2triad

Actively Exploited 0 CISA KEV List
PoC / Exploits 3 Code Available
Total RCEs 1 Remote Access
Total CVEs 52 Total Indexed
Avg. EPSS 6.69% Exploit Prob.
Latest CVE CVE-2017-12971 Aug 23

Security Vulnerability Index

Page 1 / 6
6.1 CVSS
CVE-2017-12971
Exploit Found

Cross-site scripting (XSS) vulnerability in Apache2Triad 1.5.4 allows remote attackers to inject arbitrary web script or HTML via the account parameter to phpsftpd/users.php.

EPSS: 2.90%
8.8 CVSS
CVE-2017-12970
Exploit Found

Cross-site request forgery (CSRF) vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack the authentication of authenticated users for requests that (1) add or (2) delete user accounts via a request to phpsftpd/users.php.

EPSS: 0.18%
9.8 CVSS
CVE-2017-12965
Exploit Found

Session fixation vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack web sessions via the PHPSESSID parameter.

EPSS: 22.24%
7.5 CVSS

The proxy server feature in go-pear.php in PHP PEAR 0.2.2, as used in Apache2Triad, allows remote attackers to execute arbitrary PHP code by redirecting go-pear.php to a malicious proxy server that provides a modified version of Tar.php with a malicious extractModify function.

EPSS: 1.46%