Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown
CVE-2020-8813
Disclosure Date: February 22, 2020 (last updated February 21, 2025)
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a cookie, if a guest user has the graph real-time privilege.
0
Attacker Value
Unknown
CVE-2019-16293
Disclosure Date: September 13, 2019 (last updated November 27, 2024)
The Create Discoveries feature of Open-AudIT before 3.2.0 allows an authenticated attacker to execute arbitrary OS commands via a crafted value for a URL field.
0
Attacker Value
Unknown
CVE-2018-16607
Disclosure Date: September 19, 2018 (last updated November 27, 2024)
Cross-site scripting (XSS) vulnerability in the Orgs Page in Open-AudIT Professional edition in 2.2.7 allows remote attackers to inject arbitrary web script via the Orgs name field.
0
Attacker Value
Unknown
CVE-2018-14493
Disclosure Date: July 25, 2018 (last updated November 27, 2024)
Cross-site scripting (XSS) vulnerability in the Groups Page in Open-Audit Community 2.2.6 allows remote attackers to inject arbitrary web script or HTML via the group name.
0
Attacker Value
Unknown
CVE-2018-11124
Disclosure Date: July 06, 2018 (last updated November 27, 2024)
Cross-site scripting (XSS) vulnerability in Attributes functionality in Open-AudIT Community edition before 2.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted attribute name of an Attribute.
0
Attacker Value
Unknown
CVE-2018-10314
Disclosure Date: May 10, 2018 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in Open-AudIT Community 2.2.0 allows remote attackers to inject arbitrary web script or HTML via a crafted name of a component, as demonstrated by the action parameter in the Discover -> Audit Scripts -> List Scripts -> Download section.
0
Attacker Value
Unknown
CVE-2016-6534
Disclosure Date: April 10, 2017 (last updated November 26, 2024)
Opmantek NMIS before 4.3.7c has command injection via man, finger, ping, trace, and nslookup in the tools.pl CGI script. Versions before 8.5.12G might be affected in non-default configurations.
0
Attacker Value
Unknown
CVE-2016-5642
Disclosure Date: April 10, 2017 (last updated November 26, 2024)
Opmantek NMIS before 8.5.12G has XSS via SNMP.
0