Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
searchblox vulnerabilities and exploits
(subscribe to this query)
8.8
CVSSv3
CVE-2015-0970
Cross-site request forgery (CSRF) vulnerability in SearchBlox prior to 8.2 allows remote malicious users to hijack the authentication of arbitrary users.
Searchblox Searchblox
NA
CVE-2015-3422
Cross-site scripting (XSS) vulnerability in SearchBlox prior to 8.2.1 allows remote malicious users to inject arbitrary web script or HTML via the menu2 parameter to admin/main.jsp.
Searchblox Searchblox
5.4
CVSSv3
CVE-2020-10128
SearchBlox product with version prior to 9.2.1 is vulnerable to stored cross-site scripting at multiple user input parameters. In SearchBlox products multiple parameters are not sanitized/validate properly which allows an malicious user to inject malicious JavaScript.
Searchblox Searchblox
1 Github repository
NA
CVE-2015-0968
Unrestricted file upload vulnerability in admin/uploadImage.html in SearchBlox prior to 8.2 allows remote malicious users to execute arbitrary code by uploading a file with an executable extension and the image/jpeg content type, a different vulnerability than CVE-2013-3590.
Searchblox Searchblox
8.8
CVSSv3
CVE-2018-11538
servlet/UserServlet in SearchBlox 8.6.6 has CSRF via the u_name, u_passwd1, u_passwd2, role, and X-XSRF-TOKEN POST parameters because of CSRF Token Bypass.
Searchblox Searchblox 8.6.6
1 EDB exploit
9.8
CVSSv3
CVE-2018-11586
XML external entity (XXE) vulnerability in api/rest/status in SearchBlox 8.6.7 allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.
Searchblox Searchblox 8.6.7
1 EDB exploit
10
CVSSv3
CVE-2015-7919
SearchBlox 8.3 prior to 8.3.1 allows remote malicious users to write to the config file, and consequently cause a denial of service (application crash), via unspecified vectors.
Searchblox Searchblox 8.3.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
blind SQL injection
SSRF
buffer overflow
CVE-2023-28952
CVE-2023-41822
CVE-2024-27956
CVE-2023-7028
CVE-2024-34447
CVE-2024-34460
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2