Show filters
35 Total Results
Displaying 31-35 of 35
Sort by:
Attacker Value
Unknown
CVE-2018-1000869
Disclosure Date: December 20, 2018 (last updated November 27, 2024)
phpIPAM version 1.3.2 contains a CWE-89 vulnerability in /app/admin/nat/item-add-submit.php that can result in SQL Injection.. This attack appear to be exploitable via Rough user, exploiting the vulnerability to access information he/she does not have access to.. This vulnerability appears to have been fixed in 1.4.
0
Attacker Value
Unknown
CVE-2018-10329
Disclosure Date: April 24, 2018 (last updated November 26, 2024)
app/tools/mac-lookup/index.php in phpIPAM 1.3.1 has Reflected XSS on /tools/mac-lookup/ via the mac parameter.
0
Attacker Value
Unknown
CVE-2017-15640
Disclosure Date: April 21, 2018 (last updated November 26, 2024)
app/sections/user-menu.php in phpIPAM before 1.3.1 has XSS via the ip parameter.
0
Attacker Value
Unknown
CVE-2017-6481
Disclosure Date: March 05, 2017 (last updated November 26, 2024)
Multiple Cross-Site Scripting (XSS) issues were discovered in phpipam 1.2. The vulnerabilities exist due to insufficient filtration of user-supplied data passed to several pages (instructions in app/admin/instructions/preview.php; subnetId in app/admin/powerDNS/refresh-ptr-records.php). An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.
0
Attacker Value
Unknown
CVE-2015-6529
Disclosure Date: August 20, 2015 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in phpipam 1.1.010 allow remote attackers to inject arbitrary web script or HTML via the (1) section parameter to site/error.php or (2) ip parameter to site/tools/searchResults.php.
0