« Volver al listado

Opmantek

Opmantek Open-audit: vulnerabilidades y CVE

Opmantek Open-audit tiene 16 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE16
Últimos 12 meses0
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2021-44674Media (6.5)1.0%—3 ene 2022
An information exposure issue has been discovered in Opmantek Open-AudIT 4.2.0. The vulnerability allows an authenticated attacker to read file outside of the restricted directory.
CVE-2021-40612Crítica (9.8)2.0%—22 dic 2021
An issue was discovered in Opmantek Open-AudIT after 3.5.0. Without authentication, a vulnerability in code_igniter/application/controllers/util.php allows an attacker perform command execution without echoes.
CVE-2021-44916Media (6.1)3.7%—20 dic 2021
Opmantek Open-AudIT Community 4.2.0 (Fixed in 4.3.0) is affected by a Cross Site Scripting (XSS) vulnerability. If a bad value is passed to the routine via a URL, malicious JavaScript code can be executed in the…
CVE-2021-3333Media (6.1)0.76%—5 feb 2021
Opmantek Open-AudIT 4.0.1 is affected by cross-site scripting (XSS). When outputting SQL statements for debugging, a maliciously crafted query can trigger an XSS attack. This attack only succeeds if the user is already…
CVE-2021-3130Media (5.9)1.3%—20 ene 2021
Within the Open-AudIT up to version 3.5.3 application, the web interface hides SSH secrets, Windows passwords, and SNMP strings from users using HTML 'password field' obfuscation. By using Developer tools or similar, it…
CVE-2020-11943Alta (8.8)24%—29 abr 2020
An issue was discovered in Open-AudIT 3.2.2. There is Arbitrary file upload.
CVE-2020-11942Crítica (9.8)1.2%—29 abr 2020
An issue was discovered in Open-AudIT 3.2.2. There are Multiple SQL Injections.
CVE-2020-12261Media (5.4)2.6%—28 abr 2020
Open-AudIT 3.3.0 allows an XSS attack after login.
CVE-2020-12078Alta (8.8)10.0%—28 abr 2020
An issue was discovered in Open-AudIT 3.3.1. There is shell metacharacter injection via attributes to an open-audit/configuration/ URI. An attacker can exploit this by adding an excluded IP address to the global…
CVE-2020-11941Alta (8.8)4.6%—27 abr 2020
An issue was discovered in Open-AudIT 3.2.2. There is OS Command injection in Discovery.
CVE-2020-8813Alta (8.8)74%—22 feb 2020
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a cookie, if a guest user has the graph real-time privilege.
CVE-2019-16293Alta (8.8)1.6%—13 sept 2019
The Create Discoveries feature of Open-AudIT before 3.2.0 allows an authenticated attacker to execute arbitrary OS commands via a crafted value for a URL field.
CVE-2018-16607Media (5.4)0.65%—19 sept 2018
Cross-site scripting (XSS) vulnerability in the Orgs Page in Open-AudIT Professional edition in 2.2.7 allows remote attackers to inject arbitrary web script via the Orgs name field.
CVE-2018-14493Media (6.1)41%—25 jul 2018
Cross-site scripting (XSS) vulnerability in the Groups Page in Open-Audit Community 2.2.6 allows remote attackers to inject arbitrary web script or HTML via the group name.
CVE-2018-11124Media (5.4)1.9%—6 jul 2018
Cross-site scripting (XSS) vulnerability in Attributes functionality in Open-AudIT Community edition before 2.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted attribute name of an…
CVE-2018-10314Media (5.4)1.8%—10 may 2018
Cross-site scripting (XSS) vulnerability in Open-AudIT Community 2.2.0 allows remote attackers to inject arbitrary web script or HTML via a crafted name of a component, as demonstrated by the action parameter in the…

Otros productos de Opmantek