CVE-2016-15005
CSRF tokens are generated using math/rand, which is not a cryptographically secure rander number generation, making predicting their values relatively trivial and allowing an attacker…
CSRF tokens are generated using math/rand, which is not a cryptographically secure rander number generation, making predicting their values relatively trivial and allowing an attacker…
Usage of the CORS handler may apply improper CORS headers, allowing the requester to explicitly control the value of the Access-Control-Allow-Origin header, which bypasses the…
Due to improper path santization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory. Zafiyet ile…
Due to support of Gzip compression in request bodies, as well as a lack of limiting response body sizes, a malicious server can cause a…
Improper path santiziation in github.com/goadesign/goa before v3.0.9, v2.0.10, or v1.4.3 allow remote attackers to read files outside of the intended directory. Zafiyet ile ilgili Genel…
Due to improper santization of user input, HTTPEngine.Handle allows for directory traversal, allowing an attacker to read files outside of the target directory that the…
Due to improper path santization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory. Zafiyet ile…
Due to improper path santization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory. Zafiyet ile…
Due to improper validation of caller input, validation is silently disabled if the provided expected token is malformed, causing any user supplied token to be…
Due to improper path santization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory. Zafiyet ile…