Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
searchblox vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2015-0969
SearchBlox prior to 8.2 allows remote malicious users to obtain sensitive information via a pretty=true action to the _cluster/health URI.
Searchblox Searchblox
8.8
CVSSv3
CVE-2015-0970
Cross-site request forgery (CSRF) vulnerability in SearchBlox prior to 8.2 allows remote malicious users to hijack the authentication of arbitrary users.
Searchblox Searchblox
NA
CVE-2015-3422
Cross-site scripting (XSS) vulnerability in SearchBlox prior to 8.2.1 allows remote malicious users to inject arbitrary web script or HTML via the menu2 parameter to admin/main.jsp.
Searchblox Searchblox
7.5
CVSSv3
CVE-2020-35580
A local file inclusion vulnerability in the FileServlet in all SearchBlox prior to 9.2.2 allows remote, unauthenticated users to read arbitrary files from the operating system via a /searchblox/servlet/FileServlet?col=url= request. Additionally, this may be used to read the conte...
Searchblox Searchblox
10
CVSSv3
CVE-2015-7919
SearchBlox 8.3 prior to 8.3.1 allows remote malicious users to write to the config file, and consequently cause a denial of service (application crash), via unspecified vectors.
Searchblox Searchblox 8.3.0
9.8
CVSSv3
CVE-2018-11586
XML external entity (XXE) vulnerability in api/rest/status in SearchBlox 8.6.7 allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.
Searchblox Searchblox 8.6.7
1 EDB exploit
8.8
CVSSv3
CVE-2018-11538
servlet/UserServlet in SearchBlox 8.6.6 has CSRF via the u_name, u_passwd1, u_passwd2, role, and X-XSRF-TOKEN POST parameters because of CSRF Token Bypass.
Searchblox Searchblox 8.6.6
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-49223
CVE-2024-0044
information disclosure
CVE-2024-35753
HTML injection
CVE-2024-21306
CVE-2024-35733
SQL injection
CVE-2024-35732
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2