Vulnerabilities > Inclusion of Functionality from Untrusted Control Sphere

DATE CVE VULNERABILITY TITLE RISK
2019-10-31 CVE-2013-1945 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Ruby-Lang Ruby193
ruby193 uses an insecure LD_LIBRARY_PATH setting.
local
low complexity
ruby-lang CWE-829
3.3
2019-09-27 CVE-2019-11742 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Mozilla Firefox
A same-origin policy violation occurs allowing the theft of cross-origin images through a combination of SVG filters and a <canvas> element due to an error in how same-origin policy is applied to cached image content.
network
low complexity
mozilla CWE-829
6.5
2019-09-09 CVE-2019-10666 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Librenms
An issue was discovered in LibreNMS through 1.47.
network
high complexity
librenms CWE-829
8.1
2019-09-03 CVE-2019-5479 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Larvit Larvitbase
An unintended require vulnerability in <v0.5.5 larvitbase-api may allow an attacker to load arbitrary non-production code (JavaScript file).
network
low complexity
larvit CWE-829
7.5
2019-08-30 CVE-2019-15839 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Shaosina Sina Extension for Elementor
The sina-extension-for-elementor plugin before 2.2.1 for WordPress has local file inclusion.
network
low complexity
shaosina CWE-829
7.5
2019-07-14 CVE-2019-13589 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Anjlab Paranoid2 1.1.6
The paranoid2 gem 1.1.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party.
network
low complexity
anjlab CWE-829
critical
9.8
2019-07-11 CVE-2019-4263 Inclusion of Functionality from Untrusted Control Sphere vulnerability in IBM Content Navigator 3.0.0
IBM Content Navigator 3.0CD is vulnerable to local file inclusion, allowing an attacker to access a configuration file in the ICN server.
network
low complexity
ibm CWE-829
4.3
2019-04-29 CVE-2019-11591 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Web-Dorado Contact Form
The WebDorado Contact Form plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via directory traversal, because there can be a discrepancy between the $_POST['action'] value and the $_GET['action'] value, and the latter is unsanitized.
network
low complexity
web-dorado CWE-829
8.8
2019-04-29 CVE-2019-11590 Inclusion of Functionality from Untrusted Control Sphere vulnerability in 10Web Form Maker
The 10Web Form Maker plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via directory traversal, because there can be a discrepancy between the $_POST['action'] value and the $_GET['action'] value, and the latter is unsanitized.
network
low complexity
10web CWE-829
8.8
2019-03-15 CVE-2019-9829 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Maccms 10.0
Maccms 10 allows remote attackers to execute arbitrary PHP code by entering this code in a template/default_pc/html/art Edit action.
network
low complexity
maccms CWE-829
8.8