Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
agentejo cockpit - vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2022-2713
Insufficient Session Expiration in GitHub repository cockpit-hq/cockpit before 2.2.0.
Agentejo Cockpit
9.8
CVSSv3
CVE-2020-35131
Cockpit prior to 0.6.1 allows an malicious user to inject custom PHP code and achieve Remote Command Execution via registerCriteriaFunction in lib/MongoLite/Database.php, as demonstrated by values in JSON data to the /auth/check or /auth/requestreset URI.
Agentejo Cockpit
9.8
CVSSv3
CVE-2020-35846
Agentejo Cockpit prior to 0.11.2 allows NoSQL injection via the Controller/Auth.php check function.
Agentejo Cockpit
4 Github repositories
9.8
CVSSv3
CVE-2020-35847
Agentejo Cockpit prior to 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function.
Agentejo Cockpit
2 Github repositories
9.8
CVSSv3
CVE-2020-35848
Agentejo Cockpit prior to 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function.
Agentejo Cockpit
1 Github repository
9.8
CVSSv3
CVE-2018-15540
Agentejo Cockpit performs actions on files without appropriate validation and therefore allows an malicious user to traverse the file system to unintended locations and/or access arbitrary files, aka /media/api Directory Traversal.
Agentejo Cockpit -
9.1
CVSSv3
CVE-2017-14611
SSRF (Server Side Request Forgery) in Cockpit 0.13.0 allows remote malicious users to read arbitrary files or send TCP traffic to intranet hosts via the url parameter, related to use of the discontinued aheinze/fetch_url_contents component.
Agentejo Cockpit 0.13.0
8.8
CVSSv3
CVE-2023-4195
PHP Remote File Inclusion in GitHub repository cockpit-hq/cockpit before 2.6.3.
Agentejo Cockpit
8.8
CVSSv3
CVE-2023-37650
A Cross-Site Request Forgery (CSRF) in the Admin portal of Cockpit CMS v2.5.2 allows malicious users to execute arbitrary Administrator commands.
Agentejo Cockpit
8.8
CVSSv3
CVE-2023-1313
Unrestricted Upload of File with Dangerous Type in GitHub repository cockpit-hq/cockpit before 2.4.1.
Agentejo Cockpit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
inject
CVE-2024-34001
CVE-2024-37018
LFI
CVE-2024-1275
CVE-2024-1086
CSRF
CVE-2024-31030
CVE-2024-24919
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »