Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2018-19515

In Webgalamb through 7.0, system/ajax.php functionality is supposed to be available only to the administrator. However, by using one of the bgsend, atment_sddd1xGz, or xls_bgimport query parameters, most of these methods become available to unauthenticated users.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.076
EPSS Ranking 91.4%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2018-19515
  • Ens » Webgalamb » Version: 6.0
    cpe:2.3:a:ens:webgalamb:6.0
  • Ens » Webgalamb » Version: 7.0
    cpe:2.3:a:ens:webgalamb:7.0


Contact Us

Shodan ® - All rights reserved