Show filters
69 Total Results
Displaying 21-30 of 69
Sort by:
Attacker Value
Unknown
CVE-2021-41739
Disclosure Date: May 05, 2022 (last updated February 23, 2025)
A OS Command Injection vulnerability was discovered in Artica Proxy 4.30.000000. Attackers can execute OS commands in cyrus.events.php with GET param logs and POST param rp.
0
Attacker Value
Unknown
CVE-2021-40680
Disclosure Date: April 25, 2022 (last updated February 23, 2025)
There is a Directory Traversal vulnerability in Artica Proxy (4.30.000000 SP206 through SP255, and VMware appliance 4.30.000000 through SP273) via the filename parameter to /cgi-bin/main.cgi.
0
Attacker Value
Unknown
CVE-2021-46681
Disclosure Date: February 21, 2022 (last updated October 08, 2023)
A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via module massive operation name field.
0
Attacker Value
Unknown
CVE-2021-36697
Disclosure Date: November 03, 2021 (last updated February 23, 2025)
With an admin account, the .htaccess file in Artica Pandora FMS <=755 can be overwritten with the File Manager component. The new .htaccess file contains a Rewrite Rule with a type definition. A normal PHP file can be uploaded with this new "file type" and the code can be executed with an HTTP request.
0
Attacker Value
Unknown
CVE-2021-36698
Disclosure Date: November 03, 2021 (last updated February 23, 2025)
Pandora FMS through 755 allows XSS via a new Event Filter with a crafted name.
0
Attacker Value
Unknown
CVE-2021-3832
Disclosure Date: October 06, 2021 (last updated February 23, 2025)
Integria IMS in its 5.0.92 version is vulnerable to a Remote Code Execution attack through file uploading. An unauthenticated attacker could abuse the AsyncUpload() function in order to exploit the vulnerability.
0
Attacker Value
Unknown
CVE-2021-3834
Disclosure Date: October 06, 2021 (last updated February 23, 2025)
Integria IMS in its 5.0.92 version does not filter correctly some fields related to the login.php file. An attacker could exploit this vulnerability in order to perform a cross-site scripting attack (XSS).
0
Attacker Value
Unknown
CVE-2021-3833
Disclosure Date: October 06, 2021 (last updated February 23, 2025)
Integria IMS login check uses a loose comparator ("==") to compare the MD5 hash of the password provided by the user and the MD5 hash stored in the database. An attacker with a specific formatted password could exploit this vulnerability in order to login in the system with different passwords.
0
Attacker Value
Unknown
CVE-2021-34075
Disclosure Date: June 30, 2021 (last updated February 22, 2025)
In Artica Pandora FMS <=754 in the File Manager component, there is sensitive information exposed on the client side which attackers can access.
0
Attacker Value
Unknown
CVE-2021-32098
Disclosure Date: May 07, 2021 (last updated February 22, 2025)
Artica Pandora FMS 742 allows unauthenticated attackers to perform Phar deserialization.
0