Matomo 1.2

CPE Details

Matomo 1.2
1.2
2019-11-21
12h27 +00:00
2019-11-21
12h27 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:matomo:matomo:1.2:*:*:*:*:*:*:*

Informations

Vendor

matomo

Product

matomo

Version

1.2

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2013-0195 2019-11-20 13h31 +00:00 Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: This is a different vulnerability than CVE-2013-0193 and CVE-2013-0194.
6.1
Medium
CVE-2013-0194 2019-11-20 13h30 +00:00 Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: This is a different vulnerability than CVE-2013-0193 and CVE-2013-0195.
6.1
Medium
CVE-2013-0193 2019-11-20 13h26 +00:00 Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: This is a different vulnerability than CVE-2013-0194 and CVE-2013-0195.
6.1
Medium
CVE-2015-7815 2015-11-16 18h00 +00:00 Directory traversal vulnerability in core/ViewDataTable/Factory.php in Piwik before 2.15.0 allows remote attackers to include and execute arbitrary local files via the viewDataTable parameter.
7.5
CVE-2015-7816 2015-11-16 18h00 +00:00 The DisplayTopKeywords function in plugins/Referrers/Controller.php in Piwik before 2.15.0 allows remote attackers to conduct PHP object injection attacks, conduct Server-Side Request Forgery (SSRF) attacks, and execute arbitrary PHP code via a crafted HTTP header.
7.5
CVE-2013-1844 2013-03-21 21h00 +00:00 Cross-site scripting (XSS) vulnerability in Piwik before 1.11 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
4.3
CVE-2013-2633 2013-03-21 21h00 +00:00 Piwik before 1.11 accepts input from a POST request instead of a GET request in unspecified circumstances, which might allow attackers to obtain sensitive information by leveraging the logging of parameters.
5
CVE-2012-4541 2012-11-19 11h00 +00:00 Cross-site scripting (XSS) vulnerability in Piwik before 1.9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
4.3
CVE-2011-4941 2012-09-18 18h00 +00:00 Unspecified vulnerability in Piwik 1.2 through 1.4 allows remote attackers with the view permission to execute arbitrary code via unknown attack vectors.
6.8