← Back

Craig Drummond

craig_drummond

2 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Cantata
cantata

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Craig Drummond
1Cantata
Apr 29, 2026
Feb 2, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Cantata before 1.2.2 does not restrict access to files in the play queue, which allows remote attackers to obtain sensitive information by reading the songs in the queue.
1Craig Drummond
1Cantata
Apr 29, 2026
Feb 2, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Absolute path traversal vulnerability in cantata before 1.2.2 allows local users to read arbitrary files via a full pathname in a request to the internal httpd server. NOTE: this vulnerability can be leveraged by remote...Show more
Absolute path traversal vulnerability in cantata before 1.2.2 allows local users to read arbitrary files via a full pathname in a request to the internal httpd server. NOTE: this vulnerability can be leveraged by remote attackers using CVE-2013-7301.Show less