erankor

2 exploits Active since Sep 2017
CVE-2017-14143 WRITEUP CRITICAL WRITEUP
Kaltura Server < mercury-13.1.0 - Remote Code Execution via Hardcoded Cookie Secret
The getUserzoneCookie function in Kaltura before 13.2.0 uses a hardcoded cookie secret to validate cookie signatures, which allows remote attackers to bypass an intended protection mechanism and consequently conduct PHP object injection attacks and execute arbitrary PHP code via a crafted userzone cookie.
CVSS 9.8
CVE-2017-14141 WRITEUP HIGH WRITEUP
Kaltura Server < 13.2.0 - Remote Code Execution via Wiki Decode Helper Deserialization
The wiki_decode Developer System Helper function in the admin panel in Kaltura before 13.2.0 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object.
CVSS 7.2