Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
lfi vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2022-44015
An issue exists in Simmeth Lieferantenmanager prior to 5.6. An attacker can inject raw SQL queries. By activating MSSQL features, the attacker is able to execute arbitrary commands on the MSSQL server via the xp_cmdshell extended procedure.
Simmeth Lieferantenmanager
NA
CVE-2022-44016
An issue exists in Simmeth Lieferantenmanager prior to 5.6. An attacker can download arbitrary files from the web server by abusing an API call: /DS/LM_API/api/ConfigurationService/GetImages with an '"ImagesPath":"C:\\"' value.
Simmeth Lieferantenmanager
NA
CVE-2022-44017
An issue exists in Simmeth Lieferantenmanager prior to 5.6. Due to errors in session management, an attacker can log back into a victim's account after the victim logged out - /LMS/LM/#main can be used for this. This is due to the credentials not being cleaned from the local...
Simmeth Lieferantenmanager
696
VMScore
CVE-2020-14864
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation). Supported versions that are affected are 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with...
Oracle Business Intelligence 12.2.1.3.0
Oracle Business Intelligence 12.2.1.4.0
Oracle Business Intelligence 5.5.0.0.0
NA
CVE-2023-26609
ABUS TVIP 20000-21150 devices allows remote malicious users to execute arbitrary code via shell metacharacters in the /cgi-bin/mft/wireless_mft ap field.
Abus Tvip 20000-21150 Firmware -
1 Github repository
435
VMScore
CVE-2012-5700
Multiple cross-site scripting (XSS) vulnerabilities in Baby Gekko prior to 1.2.2f allow remote malicious users to inject arbitrary web script or HTML via the (1) id parameter to admin/index.php or the (2) username or (3) password parameter in blocks/loginbox/loginbox.template.php...
Babygekko Baby Gekko 0.98
Babygekko Baby Gekko 0.99
Babygekko Baby Gekko 1.1.4
Babygekko Baby Gekko 1.1.5
Babygekko Baby Gekko 0.90
Babygekko Baby Gekko 0.91
Babygekko Baby Gekko 1.1.2
Babygekko Baby Gekko 1.1.3
Babygekko Baby Gekko 1.0.0
Babygekko Baby Gekko 1.0.1
Babygekko Baby Gekko 1.2.0
Babygekko Baby Gekko 1.2.2
Babygekko Baby Gekko 1.1.0
Babygekko Baby Gekko 1.1.1
Babygekko Baby Gekko
1 EDB exploit
685
VMScore
CVE-2012-5698
BabyGekko prior to 1.2.4 has SQL injection.
Babygekko Babygekko
1 EDB exploit
755
VMScore
CVE-2012-5699
BabyGekko prior to 1.2.4 allows PHP file inclusion.
Babygekko Babygekko
1 EDB exploit
445
VMScore
CVE-2017-6100
tcpdf prior to 6.2.0 uploads files from the server generating PDF-files to an external FTP.
Tcpdf Project Tcpdf
645
VMScore
CVE-2012-0298
The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x prior to 5.0.3 allow remote malicious users to (1) read or (2) delete arbitrary files via unspecified vectors.
Symantec Web Gateway 5.0
Symantec Web Gateway 5.0.2
Symantec Web Gateway 5.0.1
1 EDB exploit
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-49223
CVE-2024-0044
information disclosure
CVE-2024-35753
HTML injection
CVE-2024-21306
CVE-2024-35733
SQL injection
CVE-2024-35732
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »