Show filters
64 Total Results
Displaying 11-20 of 64
Sort by:
Attacker Value
Unknown
CVE-2022-1356
Disclosure Date: May 12, 2022 (last updated February 23, 2025)
cnMaestro is vulnerable to a local privilege escalation. By default, a user does not have root privileges. However, a user can run scripts as sudo, which could allow an attacker to gain root privileges when running user scripts outside allowed commands.
0
Attacker Value
Unknown
CVE-2022-1360
Disclosure Date: May 12, 2022 (last updated February 23, 2025)
The affected On-Premise cnMaestro is vulnerable to execution of code on the cnMaestro hosting server. This could allow a remote attacker to change server configuration settings.
0
Attacker Value
Unknown
CVE-2022-1362
Disclosure Date: May 12, 2022 (last updated February 23, 2025)
The affected On-Premise cnMaestro is vulnerable inside a specific route where a user can upload a crafted package to the system. An attacker could abuse this user-controlled data to execute arbitrary commands on the server.
0
Attacker Value
Unknown
CVE-2022-1358
Disclosure Date: May 12, 2022 (last updated February 23, 2025)
The affected On-Premise is vulnerable to data exfiltration through improper neutralization of special elements used in an SQL command. This could allow an attacker to exfiltrate and dump all data held in the cnMaestro database.
0
Attacker Value
Unknown
CVE-2022-1359
Disclosure Date: May 12, 2022 (last updated February 23, 2025)
The affected On-Premise cnMaestro is vulnerable to an arbitrary file-write through improper limitation of a pathname to a restricted directory inside a specific route. If an attacker supplied path traversal charters (../) as part of a filename, the server will save the file where the attacker chooses. This could allow an attacker to write any data to any file in the server.
0
Attacker Value
Unknown
CVE-2022-1357
Disclosure Date: May 12, 2022 (last updated February 23, 2025)
The affected On-Premise cnMaestro allows an unauthenticated attacker to access the cnMaestro server and execute arbitrary code in the privileges of the web server. This lack of validation could allow an attacker to append arbitrary data to the logger command.
0
Attacker Value
Unknown
CVE-2022-1361
Disclosure Date: May 12, 2022 (last updated February 23, 2025)
The affected On-Premise cnMaestro is vulnerable to a pre-auth data exfiltration through improper neutralization of special elements used in an SQL command. This could allow an attacker to exfiltrate data about other user’s accounts and devices.
0
Attacker Value
Unknown
CVE-2022-1390
Disclosure Date: April 25, 2022 (last updated February 23, 2025)
The Admin Word Count Column WordPress plugin through 2.2 does not validate the path parameter given to readfile(), which could allow unauthenticated attackers to read arbitrary files on server running old version of PHP susceptible to the null byte technique. This could also lead to RCE by using a Phar Deserialization technique
0
Attacker Value
Unknown
CVE-2021-45685
Disclosure Date: December 27, 2021 (last updated February 23, 2025)
An issue was discovered in the columnar crate through 2021-01-07 for Rust. ColumnarReadExt::read_typed_vec may read from uninitialized memory locations.
0
Attacker Value
Unknown
CVE-2020-19137
Disclosure Date: September 08, 2021 (last updated February 23, 2025)
Incorrect Access Control in Autumn v1.0.4 and earlier allows remote attackers to obtain clear-text login credentials via the component "autumn-cms/user/getAllUser/?page=1&limit=10".
0