Show filters
18 Total Results
Displaying 1-10 of 18
Sort by:
Attacker Value
Unknown
CVE-2021-44674
Disclosure Date: January 03, 2022 (last updated February 23, 2025)
An information exposure issue has been discovered in Opmantek Open-AudIT 4.2.0. The vulnerability allows an authenticated attacker to read file outside of the restricted directory.
0
Attacker Value
Unknown
CVE-2021-40612
Disclosure Date: December 22, 2021 (last updated October 07, 2023)
An issue was discovered in Opmantek Open-AudIT after 3.5.0. Without authentication, a vulnerability in code_igniter/application/controllers/util.php allows an attacker perform command execution without echoes.
0
Attacker Value
Unknown
CVE-2021-44916
Disclosure Date: December 20, 2021 (last updated February 23, 2025)
Opmantek Open-AudIT Community 4.2.0 (Fixed in 4.3.0) is affected by a Cross Site Scripting (XSS) vulnerability. If a bad value is passed to the routine via a URL, malicious JavaScript code can be executed in the victim's browser.
0
Attacker Value
Unknown
CVE-2021-3333
Disclosure Date: February 05, 2021 (last updated February 22, 2025)
Opmantek Open-AudIT 4.0.1 is affected by cross-site scripting (XSS). When outputting SQL statements for debugging, a maliciously crafted query can trigger an XSS attack. This attack only succeeds if the user is already logged in to Open-AudIT before they click the malicious link.
0
Attacker Value
Unknown
CVE-2021-3130
Disclosure Date: January 20, 2021 (last updated February 22, 2025)
Within the Open-AudIT up to version 3.5.3 application, the web interface hides SSH secrets, Windows passwords, and SNMP strings from users using HTML 'password field' obfuscation. By using Developer tools or similar, it is possible to change the obfuscation so that the credentials are visible.
0
Attacker Value
Unknown
CVE-2020-11942
Disclosure Date: April 29, 2020 (last updated February 21, 2025)
An issue was discovered in Open-AudIT 3.2.2. There are Multiple SQL Injections.
0
Attacker Value
Unknown
CVE-2020-11943
Disclosure Date: April 29, 2020 (last updated February 21, 2025)
An issue was discovered in Open-AudIT 3.2.2. There is Arbitrary file upload.
0
Attacker Value
Unknown
CVE-2020-12261
Disclosure Date: April 28, 2020 (last updated February 21, 2025)
Open-AudIT 3.3.0 allows an XSS attack after login.
0
Attacker Value
Unknown
CVE-2020-12078
Disclosure Date: April 28, 2020 (last updated February 21, 2025)
An issue was discovered in Open-AudIT 3.3.1. There is shell metacharacter injection via attributes to an open-audit/configuration/ URI. An attacker can exploit this by adding an excluded IP address to the global discovery settings (internally called exclude_ip). This exclude_ip value is passed to the exec function in the discoveries_helper.php file (inside the all_ip_list function) without being filtered, which means that the attacker can provide a payload instead of a valid IP address.
0
Attacker Value
Unknown
CVE-2020-11941
Disclosure Date: April 27, 2020 (last updated February 21, 2025)
An issue was discovered in Open-AudIT 3.2.2. There is OS Command injection in Discovery.
0