Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown
CVE-2021-43458
Disclosure Date: April 04, 2022 (last updated October 07, 2023)
An Unquoted Service Path vulnerability exits in Vembu BDR 4.2.0.1 via a specially crafted file in the (1) hsflowd, (2) VembuBDR360Agent, or (3) VembuOffice365Agent service paths.
0
Attacker Value
Unknown
CVE-2021-26472
Disclosure Date: June 08, 2021 (last updated February 22, 2025)
In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1 installed on Windows, the http API located at /consumerweb/secure/download.php. Using this command argument an unauthenticated attacker can execute arbitrary OS commands with SYSTEM privileges.
0
Attacker Value
Unknown
CVE-2021-26473
Disclosure Date: June 08, 2021 (last updated February 22, 2025)
In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1 the http API located at /sgwebservice_o.php action logFilePath allows an attacker to write arbitrary files in the context of the web server process. These files can then be executed remotely by calling the file via the web server.
0
Attacker Value
Unknown
CVE-2021-26474
Disclosure Date: June 08, 2021 (last updated February 22, 2025)
Various Vembu products allow an attacker to execute a (non-blind) http-only Cross Site Request Forgery (Other products or versions of products in this family may be affected too.)
0
Attacker Value
Unknown
CVE-2021-26471
Disclosure Date: June 08, 2021 (last updated November 28, 2024)
In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1, the http API located at /sgwebservice_o.php accepts a command argument. Using this command argument an unauthenticated attacker can execute arbitrary shell commands.
0
Attacker Value
Unknown
CVE-2014-10079
Disclosure Date: February 23, 2019 (last updated November 27, 2024)
In Vembu StoreGrid 4.4.x, the front page of the server web interface leaks the private IP address in the "ipaddress" hidden form value of the HTML source code, which is disclosed because of incorrect processing of an index.php/ trailing slash.
0
Attacker Value
Unknown
CVE-2014-10078
Disclosure Date: February 23, 2019 (last updated November 27, 2024)
Vembu StoreGrid 4.4.x has XSS in interface/registercustomer/onlineregsuccess.php, interface/registerreseller/onlineregfailure.php, interface/registerclient/onlineregfailure.php, and interface/registercustomer/onlineregfailure.php.
0