Unspecified vulnerability in MySource Classic 2.14.6, and possibly earlier, allows remote authenticated users, with superuser privileges, to inject arbitrary PHP code via unspecified vectors related to the Equation attribute in Web_Extensions - Notitia (I/II). NOTE: due to lack of details, it is not clear whether this issue is file inclusion, static code injection, or another type of issue.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| squiz | mysource_classic | * |
MySource Matrix 3.8 and earlier, and MySource 2.x, allow remote attackers to use the application as an HTTP proxy server via the sq_remote_page_url parameter to access arbitrary sites with the server's IP address and conduct cross-site scripting (XSS) attacks. NOTE: the researcher reports that "The vendor does not consider this a vulnerability.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| squiz | mysource_classic | * |
| squiz | mysource_matrix | * |
MySource Matrix after 3.8 allows remote attackers to use the application as an HTTP proxy server via a MIME encoded URL in the sq_content_src parameter to access arbitrary sites with the server's IP address and conduct cross-site scripting (XSS) attacks. NOTE: the researcher reports that "The vendor does not consider this a vulnerability.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| squiz | mysource_matrix | 3.8.5 |
| squiz | mysource_matrix | 3.10.1 |
| squiz | mysource_matrix | 3.8.4 |
| squiz | mysource_matrix | 3.8 |
| squiz | mysource_matrix | 3.10 |
| squiz | mysource_matrix | 3.8.3 |
| squiz | mysource_matrix | 3.8.2 |
| squiz | mysource_matrix | 3.8.6a |
Multiple cross-site scripting (XSS) vulnerabilities in char_map.php in MySource Matrix 3.28.3 allow remote attackers to inject arbitrary web script or HTML via the (1) height or (2) width parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| squiz | mysource_matrix | 3.28.3 |
An issue was discovered in Squiz Matrix from 5.3 through to 5.3.6.1 and 5.4.1.3. An information disclosure caused by a Path Traversal issue in the 'File Bridge' plugin allowed the existence of files outside of the bridged path to be confirmed.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| squiz | matrix | * |
| squiz | matrix | 5.4.1.3 |
An issue was discovered in Squiz Matrix before 5.3.6.1 and 5.4.x before 5.4.1.3. There are multiple reflected Cross-Site Scripting (XSS) issues in Matrix WYSIWYG plugins.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| squiz | matrix | 5.4.0.3 |
| squiz | matrix | 5.4.1.0 |
| squiz | matrix | * |
| squiz | matrix | 5.4.1.2 |
| squiz | matrix | 5.4.0.0 |
| squiz | matrix | 5.4.0.2 |
| squiz | matrix | 5.4.0.1 |
| squiz | matrix | 5.4.1.1 |
An issue was discovered in Squiz Matrix before 5.3.6.1 and 5.4.x before 5.4.1.3. Authenticated users with permissions to edit design assets can cause Remote Code Execution (RCE) via a maliciously crafted time_format tag.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-94,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| squiz | matrix | 5.4.0.3 |
| squiz | matrix | 5.4.1.0 |
| squiz | matrix | * |
| squiz | matrix | 5.4.1.2 |
| squiz | matrix | 5.4.0.0 |
| squiz | matrix | 5.4.0.2 |
| squiz | matrix | 5.4.0.1 |
| squiz | matrix | 5.4.1.1 |