Vulnerabilities (CVE)

Filtered by vendor Scott Parish Subscribe
Filtered by product Chuid
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-0144 1 Scott Parish 1 Chuid 2024-02-04 7.5 HIGH N/A
Directory traversal vulnerability in chuid 1.2 and earlier allows remote attackers to change the ownership of files outside of the upload directory via a .. (dot dot) attack.
CVE-2002-0145 1 Scott Parish 1 Chuid 2024-02-04 7.5 HIGH N/A
chuid 1.2 and earlier does not properly verify the ownership of files that will be changed, which allows remote attackers to change files owned by other users, such as root.