Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
lfi vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv3
CVE-2022-44016
An issue exists in Simmeth Lieferantenmanager prior to 5.6. An attacker can download arbitrary files from the web server by abusing an API call: /DS/LM_API/api/ConfigurationService/GetImages with an '"ImagesPath":"C:\\"' value.
Simmeth Lieferantenmanager
7.5
CVSSv3
CVE-2022-44017
An issue exists in Simmeth Lieferantenmanager prior to 5.6. Due to errors in session management, an attacker can log back into a victim's account after the victim logged out - /LMS/LM/#main can be used for this. This is due to the credentials not being cleaned from the local...
Simmeth Lieferantenmanager
9.8
CVSSv3
CVE-2012-5699
BabyGekko prior to 1.2.4 allows PHP file inclusion.
Babygekko Babygekko
1 EDB exploit
7.2
CVSSv3
CVE-2023-26609
ABUS TVIP 20000-21150 devices allows remote malicious users to execute arbitrary code via shell metacharacters in the /cgi-bin/mft/wireless_mft ap field.
Abus Tvip 20000-21150 Firmware -
1 Github repository
8.8
CVSSv3
CVE-2012-5698
BabyGekko prior to 1.2.4 has SQL injection.
Babygekko Babygekko
1 EDB exploit
NA
CVE-2012-5700
Multiple cross-site scripting (XSS) vulnerabilities in Baby Gekko prior to 1.2.2f allow remote malicious users to inject arbitrary web script or HTML via the (1) id parameter to admin/index.php or the (2) username or (3) password parameter in blocks/loginbox/loginbox.template.php...
Babygekko Baby Gekko 0.98
Babygekko Baby Gekko 0.99
Babygekko Baby Gekko 1.1.4
Babygekko Baby Gekko 1.1.5
Babygekko Baby Gekko 0.90
Babygekko Baby Gekko 0.91
Babygekko Baby Gekko 1.1.2
Babygekko Baby Gekko 1.1.3
Babygekko Baby Gekko 1.0.0
Babygekko Baby Gekko 1.0.1
Babygekko Baby Gekko 1.2.0
Babygekko Baby Gekko 1.2.2
Babygekko Baby Gekko 1.1.0
Babygekko Baby Gekko 1.1.1
Babygekko Baby Gekko
1 EDB exploit
7.5
CVSSv3
CVE-2017-6100
tcpdf prior to 6.2.0 uploads files from the server generating PDF-files to an external FTP.
Tcpdf Project Tcpdf
NA
CVE-2013-1645
Directory traversal vulnerability in Open-Xchange Server prior to 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the publication template path.
Open-xchange Open-xchange Server 6.22.1
Open-xchange Open-xchange Server 6.22.0
Open-xchange Open-xchange Server 6.20.7
1 EDB exploit
NA
CVE-2013-1647
Multiple CRLF injection vulnerabilities in Open-Xchange Server prior to 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 allow remote malicious users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted parameter, as demonstrated by...
Open-xchange Open-xchange Server 6.22.1
Open-xchange Open-xchange Server 6.22.0
Open-xchange Open-xchange Server 6.20.7
1 EDB exploit
NA
CVE-2013-1649
Open-Xchange Server prior to 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 uses the crypt and SHA-1 algorithms for password hashing, which makes it easier for context-dependent malicious users to obtain cleartext passwords via a brute-force attack.
Open-xchange Open-xchange Server 6.22.0
Open-xchange Open-xchange Server 6.22.1
Open-xchange Open-xchange Server 6.20.7
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-27322
CVE-2006-4304
wireless
CVE-2023-23022
local file inclusion
CVE-2024-27058
CVE-2024-33820
open redirect
CVE-2024-27079
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »