Vulnerabilities > Inclusion of Functionality from Untrusted Control Sphere

DATE CVE VULNERABILITY TITLE RISK
2020-09-19 CVE-2020-25788 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Tt-Rss Tiny RSS 17.4
An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16.
network
tt-rss CWE-829
6.8
2020-08-11 CVE-2020-13175 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Teradici products
The Management Interface of the Teradici Cloud Access Connector and Cloud Access Connector Legacy for releases prior to April 20, 2020 (v15 and earlier for Cloud Access Connector) contains a local file inclusion vulnerability which allows an unauthenticated remote attacker to leak LDAP credentials via a specially crafted HTTP request.
network
low complexity
teradici CWE-829
5.0
2020-06-09 CVE-2020-13977 Inclusion of Functionality from Untrusted Control Sphere vulnerability in multiple products
Nagios 4.4.5 allows an attacker, who already has administrative access to change the "URL for JSON CGIs" configuration setting, to modify the Alert Histogram and Trends code via crafted versions of the archivejson.cgi, objectjson.cgi, and statusjson.cgi files.
network
low complexity
nagios fedoraproject CWE-829
4.9
2020-04-01 CVE-2020-10865 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Avast Antivirus
An issue was discovered in Avast Antivirus before 20.
network
low complexity
avast CWE-829
5.0
2020-01-29 CVE-2013-3321 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Netapp Oncommand System Manager 2.0.2/2.1
NetApp OnCommand System Manager 2.1 and earlier allows remote attackers to include arbitrary files through specially crafted requests to the "diagnostic" page using the SnapMirror log path parameter.
network
netapp CWE-829
6.0
2020-01-28 CVE-2013-4582 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Gitlab and Gitlab-Shell
The (1) create_branch, (2) create_tag, (3) import_project, and (4) fork_project functions in lib/gitlab_projects.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote authenticated users to include information from local files into the metadata of a Git repository via the web interface.
network
low complexity
gitlab CWE-829
4.0
2020-01-22 CVE-2012-4919 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Gallery Project Gallery 1.4
Gallery Plugin1.4 for WordPress has a Remote File Include Vulnerability
network
low complexity
gallery-project CWE-829
7.5
2020-01-08 CVE-2019-17014 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Mozilla Firefox
If an image had not loaded correctly (such as when it is not actually an image), it could be dragged and dropped cross-domain, resulting in a cross-origin information leak.
network
mozilla CWE-829
4.3
2019-11-06 CVE-2019-8154 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Magento
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1.
network
low complexity
magento CWE-829
6.5
2019-10-31 CVE-2013-1945 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Ruby-Lang Ruby193
ruby193 uses an insecure LD_LIBRARY_PATH setting.
local
low complexity
ruby-lang CWE-829
2.1