13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2019-25237
SOL GPON/EPON OLT Platform Web
8.7
HIGH
EPSS
0.1%
2019 CWE-863 2 PoCs

V-SOL GPON/EPON OLT Platform v2.03 contains a privilege escalation vulnerability that allows normal users to gain administrative access by manipulating the user role parameter. Attackers can send a crafted HTTP POST request to the user management endpoint with 'user_role_mod' set to integer value '1' to elevate their privileges.

CVE-2019-25243
FaceSentry Access Control System Web
8.7
HIGH
EPSS
1.1%
2019 CWE-78 2 PoCs

FaceSentry 6.4.8 contains an authenticated remote command injection vulnerability in pingTest.php and tcpPortTest.php scripts. Attackers can exploit unsanitized input parameters to inject and execute arbitrary shell commands with root privileges by manipulating the 'strInIP' and 'strInPort' parameters.

CVE-2019-11043
🔥 KEV PHP Web
8.7
HIGH
EPSS
94.1%
2019 CWE-120 25 PoCs

In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.

CVE-2019-25355
gSOAP Web
8.7
HIGH
EPSS
0.5%
2019 CWE-22 1 PoC

gSOAP 2.8 contains a directory traversal vulnerability that allows unauthenticated attackers to access system files by manipulating HTTP path traversal techniques. Attackers can retrieve sensitive files like /etc/passwd by sending crafted GET requests with multiple '../' directory traversal sequences.

CVE-2019-25480
ARMBot Web
8.7
HIGH
EPSS
0.1%
2019 CWE-22 1 PoC

ARMBot contains an unrestricted file upload vulnerability in upload.php that allows unauthenticated attackers to upload arbitrary files by manipulating the file parameter with path traversal sequences. Attackers can upload PHP files with traversal payloads ../public_html/ to write executable code to the web root and achieve remote code execution.

CVE-2019-25239
GPON/EPON OLT Platform Web
8.7
HIGH
EPSS
0.1%
2019 CWE-552 2 PoCs

V-SOL GPON/EPON OLT Platform 2.03 contains an unauthenticated information disclosure vulnerability that allows attackers to download configuration files via direct object reference. Attackers can retrieve sensitive configuration data by sending HTTP GET requests to the usrcfg.conf endpoint, potentially enabling authentication bypass and system access.

CVE-2019-25515
Hazir Haber Sitesi Scripti Web Database
8.7
HIGH
EPSS
0.9%
2019 CWE-89 1 PoC

Jettweb PHP Hazir Haber Sitesi Scripti V3 contains an authentication bypass vulnerability in the login.php administration panel that allows unauthenticated attackers to gain administrative access by submitting crafted SQL syntax. Attackers can bypass authentication by submitting equals signs and 'or' operators as username and password parameters to access the administration panel without valid credentials.

CVE-2019-25478
GetGo Download Manager Web
8.7
HIGH
EPSS
0.1%
2019 CWE-787 1 PoC

GetGo Download Manager 6.2.2.3300 contains a buffer overflow vulnerability that allows remote attackers to cause denial of service by sending HTTP responses with excessively long headers. Attackers can craft malicious HTTP responses with oversized header values to crash the application and make it unavailable.

CVE-2019-25352
Crystal Live HTTP Server Web Windows
8.7
HIGH
EPSS
0.6%
2019 CWE-22 1 PoC

Crystal Live HTTP Server 6.01 contains a directory traversal vulnerability that allows remote attackers to access system files by manipulating URL path segments. Attackers can use multiple '../' sequences to navigate outside the web root and retrieve sensitive configuration files like Windows system files.

CVE-2019-25671
VA MAX Web
8.7
HIGH
EPSS
0.5%
2019 CWE-22 1 PoC

VA MAX 8.3.4 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary commands by injecting shell metacharacters into the mtu_eth0 parameter. Attackers can send POST requests to the changeip.php endpoint with malicious payload in the mtu_eth0 field to execute commands as the apache user.

CVE-2019-25630
PhreeBooks ERP Web
8.7
HIGH
EPSS
0.8%
2019 CWE-434 1 PoC

PhreeBooks ERP 5.2.3 contains an arbitrary file upload vulnerability in the Image Manager component that allows authenticated attackers to upload malicious files by submitting requests to the image upload endpoint. Attackers can upload PHP files through the imgFile parameter to the bizuno/image/manager endpoint and execute them via the bizunoFS.php script for remote code execution.

CVE-2019-25673
Laravel File Manager Web
8.7
HIGH
EPSS
0.1%
2019 CWE-434 1 PoC

UniSharp Laravel File Manager v2.0.0-alpha7 and v2.0 contain an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by sending multipart form data to the upload endpoint. Attackers can upload PHP files with the type parameter set to Files and execute arbitrary code by accessing the uploaded file through the working directory path.

CVE-2019-25579
phpTransformer Web
8.7
HIGH
EPSS
3.1%
2019 CWE-22 1 PoC

phpTransformer 2016.9 contains a directory traversal vulnerability that allows unauthenticated attackers to access arbitrary files by manipulating the path parameter. Attackers can send requests to the jQueryFileUploadmaster server endpoint with traversal sequences ../../../../../../ to list and retrieve files outside the intended directory.

CVE-2021-47888
Textpattern Web
8.7
HIGH
EPSS
0.5%
2021 CWE-434 1 PoC

Textpattern versions prior to 4.8.3 contain an authenticated remote code execution vulnerability that allows logged-in users to upload malicious PHP files. Attackers can upload a PHP file with a shell command execution payload and execute arbitrary commands by accessing the uploaded file through a specific URL parameter.

CVE-2021-47701
OpenBMCS Web
8.7
HIGH
EPSS
0.1%
2021 CWE-862 2 PoCs

OpenBMCS 2.4 allows an attacker to escalate privileges from a read user to an admin user by manipulating permissions and exploiting a vulnerability in the update_user_permissions.php script. Attackers can submit a malicious HTTP POST request to PHP scripts in '/plugins/useradmin/' directory.

CVE-2021-47849
Mini Mouse Web
8.7
HIGH
EPSS
0.0%
2021 CWE-22 1 PoC

Mini Mouse 9.3.0 contains a path traversal vulnerability that allows attackers to access sensitive system directories through the device information endpoint. Attackers can retrieve file lists from system directories like /usr, /etc, and /var by manipulating file path parameters in API requests.

CVE-2021-4463
BEMS API Web
8.7
HIGH
EPSS
0.2%
2021 CWE-552 2 PoCs

Longjing Technology BEMS API versions up to and including 1.21 contains an unauthenticated arbitrary file download vulnerability in the 'downloads' endpoint. The 'fileName' parameter is not properly sanitized, allowing attackers to craft traversal sequences and access sensitive files outside the intended directory.

CVE-2021-47904
PhreeBooks Web
8.7
HIGH
EPSS
0.5%
2021 CWE-434 2 PoCs

PhreeBooks 5.2.3 contains an authenticated file upload vulnerability in the Image Manager that allows remote code execution. Attackers can upload a malicious PHP web shell by exploiting unrestricted file type uploads to gain command execution on the server.

CVE-2021-47704
OpenBMCS Web Database
8.7
HIGH
EPSS
0.0%
2021 CWE-89 2 PoCs

OpenBMCS 2.4 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting arbitrary SQL code. Attackers can send GET requests to /debug/obix_test.php with malicious 'id' values to extract database information.

CVE-2021-47795
GeoVision Geowebserver Web
8.7
HIGH
EPSS
0.0%
2021 CWE-22 1 PoC

GeoVision GeoWebServer 5.3.3 contains multiple vulnerabilities including local file inclusion, cross-site scripting, and remote code execution through improper input sanitization. Attackers can exploit the WebStrings.srf endpoint by manipulating path traversal and injection parameters to access system files and execute malicious scripts.