V. Paulikas

2 exploits Active since Dec 2014
CVE-2014-9302 EXPLOITDB text WRITEUP
Alfresco Community Edition < 5.0.a - Server-Side Request Forgery via CMIS Browser Servlet URL Parameter
Server-side request forgery (SSRF) vulnerability in the cmisbrowser servlet in Content Management Interoperability Service (CMIS) in Alfresco Community Edition 5.0.a and earlier allows remote attackers to trigger outbound requests via a crafted URI in the url parameter.
CVE-2014-9301 EXPLOITDB text WRITEUP
Alfresco Community Edition <5.0.a - SSRF
Server-side request forgery (SSRF) vulnerability in the proxy servlet in Alfresco Community Edition before 5.0.a allows remote attackers to trigger outbound requests to intranet servers, conduct port scans, and read arbitrary files via a crafted URI in the endpoint parameter.