296,224
Total vulnerabilities in the database
Pydio 6.0.8 mishandles error reporting when a directory allows unauthenticated uploads, and the remote-upload option is used with the http://localhost:22 URL. The attacker can obtain sensitive information such as the name of the user who created that directory and other internal server information.
Software | From | Fixed in |
---|---|---|
pydio / pydio | 6.0.8 | 6.0.8.x |