Show filters
15 Total Results
Displaying 11-15 of 15
Sort by:
Attacker Value
Unknown
CVE-2024-2449
Disclosure Date: March 22, 2024 (last updated February 11, 2025)
A cross-site request forgery vulnerability has been identified in LoadMaster. It is possible for a malicious actor, who has prior knowledge of the IP or hostname of a specific LoadMaster, to direct an authenticated LoadMaster administrator to a third-party site. In such a scenario, the CSRF payload hosted on the malicious site would execute HTTP transactions on behalf of the LoadMaster administrator.
0
Attacker Value
Unknown
CVE-2024-2448
Disclosure Date: March 22, 2024 (last updated February 12, 2025)
An OS command injection vulnerability has been identified in LoadMaster. An authenticated UI user with any permission settings may be able to inject commands into a UI component using a shell command resulting in OS command injection.
0
Attacker Value
Unknown
CVE-2024-1212
Disclosure Date: February 21, 2024 (last updated November 20, 2024)
Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.
0
Attacker Value
Unknown
CVE-2014-5287
Disclosure Date: January 08, 2020 (last updated February 21, 2025)
A Bash script injection vulnerability exists in Kemp Load Master 7.1-16 and earlier due to a failure to sanitize input in the Web User Interface (WUI).
0
Attacker Value
Unknown
CVE-2018-9091
Disclosure Date: May 25, 2018 (last updated November 26, 2024)
A critical vulnerability in the KEMP LoadMaster Operating System (LMOS) 6.0.44 through 7.2.41.2 and Long Term Support (LTS) LMOS before 7.1.35.5 related to Session Management could allow an unauthenticated, remote attacker to bypass security protections, gain system privileges, and execute elevated commands such as ls, ps, cat, etc., thereby compromising the system. Through this remote execution, in certain cases, exposure of sensitive system data such as certificates, private keys, and other information may be possible.
0