fibranet monitorix CVE Vulnerabilities (4)

CVEs: 4 CPE versions: View versions table

Summary

This page lists publicly disclosed CVE vulnerabilities affecting fibranet monitorix (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.

Showing 14 of 4 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2021-3325 Monitorix 3.13.0 allows remote attackers to bypass Basic Authentication in a default installation (i.e., an installation without a hosts_deny option). This issue occurred because a new access-control feature was introduced without considering that some exiting installations became unsafe, upon an update to 3.13.0, unless the new feature was immediately configured. [email protected] 9.8 1.38% 2021-01-27 2024-11-21
CVE-2013-7071 Cross-site scripting (XSS) vulnerability in the handle_request function in lib/HTTPServer.pm in Monitorix before 3.4.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. [email protected] 6.1 0.58% 2019-12-31 2024-11-21
CVE-2013-7070 The handle_request function in lib/HTTPServer.pm in Monitorix before 3.3.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the URI. [email protected] 9.8 4.63% 2019-12-31 2024-11-21
CVE-2018-7649 Monitorix before 3.10.1 allows XSS via CGI variables. [email protected] 6.1 0.27% 2018-08-02 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence