Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown

CVE-2020-8813

Disclosure Date: February 22, 2020 (last updated February 21, 2025)
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a cookie, if a guest user has the graph real-time privilege.
Attacker Value
Unknown

CVE-2019-16293

Disclosure Date: September 13, 2019 (last updated November 27, 2024)
The Create Discoveries feature of Open-AudIT before 3.2.0 allows an authenticated attacker to execute arbitrary OS commands via a crafted value for a URL field.
Attacker Value
Unknown

CVE-2018-16607

Disclosure Date: September 19, 2018 (last updated November 27, 2024)
Cross-site scripting (XSS) vulnerability in the Orgs Page in Open-AudIT Professional edition in 2.2.7 allows remote attackers to inject arbitrary web script via the Orgs name field.
0
Attacker Value
Unknown

CVE-2018-14493

Disclosure Date: July 25, 2018 (last updated November 27, 2024)
Cross-site scripting (XSS) vulnerability in the Groups Page in Open-Audit Community 2.2.6 allows remote attackers to inject arbitrary web script or HTML via the group name.
0
Attacker Value
Unknown

CVE-2018-11124

Disclosure Date: July 06, 2018 (last updated November 27, 2024)
Cross-site scripting (XSS) vulnerability in Attributes functionality in Open-AudIT Community edition before 2.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted attribute name of an Attribute.
0
Attacker Value
Unknown

CVE-2018-10314

Disclosure Date: May 10, 2018 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in Open-AudIT Community 2.2.0 allows remote attackers to inject arbitrary web script or HTML via a crafted name of a component, as demonstrated by the action parameter in the Discover -> Audit Scripts -> List Scripts -> Download section.
0
Attacker Value
Unknown

CVE-2016-6534

Disclosure Date: April 10, 2017 (last updated November 26, 2024)
Opmantek NMIS before 4.3.7c has command injection via man, finger, ping, trace, and nslookup in the tools.pl CGI script. Versions before 8.5.12G might be affected in non-default configurations.
0
Attacker Value
Unknown

CVE-2016-5642

Disclosure Date: April 10, 2017 (last updated November 26, 2024)
Opmantek NMIS before 8.5.12G has XSS via SNMP.
0