Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Nickolla

#22309of 53,624
10Total CVSS
Vulnerabilities · 2
Medium
2
PT-2014-3343
5.0
2014-02-02
Cantata · Cantata · CVE-2013-7300
**Name of the Vulnerable Software and Affected Versions** cantata versions prior to 1.2.2 **Description** The issue allows local users to read arbitrary files via a full pathname in a request to the internal httpd server. It can also be leveraged by remote attackers. **Recommendations** For versions prior to 1.2.2, update to version 1.2.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the internal httpd server to minimize the risk of exploitation.
PT-2014-3344
5.0
2014-02-02
Taglib · Cantata · CVE-2013-7301
**Name of the Vulnerable Software and Affected Versions** Cantata versions prior to 1.2.2 **Description** The issue allows remote attackers to obtain sensitive information by reading the songs in the play queue due to a lack of access restriction to files in the play queue. **Recommendations** For versions prior to 1.2.2, update to version 1.2.2 or later to resolve the issue.