Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
i-doit i-doit vulnerabilities and exploits
(subscribe to this query)
668
VMScore
CVE-2019-1010248
Synetics GmbH I-doit 1.12 and previous versions is affected by: SQL Injection. The impact is: Unauthenticated mysql database access. The component is: Web login form. The attack vector is: An attacker can exploit the vulnerability by sending a malicious HTTP POST request. The fix...
I-doit I-doit
383
VMScore
CVE-2020-13825
A cross-site scripting (XSS) vulnerability in i-doit 1.14.2 allows remote malicious users to inject arbitrary web script or HTML via the viewMode, tvMode, tvType, objID, catgID, objTypeID, or editMode parameter.
I-doit I-doit
605
VMScore
CVE-2020-13826
A CSV injection (aka Excel Macro Injection or Formula Injection) issue in i-doit 1.14.2 allows an malicious user to execute arbitrary commands via a Title parameter that is mishandled in a CSV export.
I-doit I-doit
435
VMScore
CVE-2019-6965
An XSS issue exists in i-doit Open 1.12 via the src/tools/php/qr/qr.php url parameter.
I-doit I-doit 1.12
1 EDB exploit
578
VMScore
CVE-2018-20159
i-doit open 1.11.2 allows Remote Code Execution because ZIP archives are mishandled. It has an upload feature that allows an authenticated user with the administrator role to upload arbitrary files to the main website directory. Exploitation involves uploading a ".php" ...
I-doit I-doit 1.11.2
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-5834
CVE-2024-30100
CVE-2024-4577
physical
dos
CVE-2024-30099
CVE-2024-27801
CVE-2024-32146
logic flaw
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2