Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In March 2021
EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted JSON/XML input to a cgi/ajax/phrase URI.
CVSS Score
9.8
EPSS Score
0.065
Published
2021-03-01
EPrints 3.4.2 allows remote attackers to execute arbitrary commands via crafted input to the verb parameter in a cgi/toolbox/toolbox URI.
CVSS Score
8.8
EPSS Score
0.023
Published
2021-03-01
CVE-2021-27876
Known exploited
An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a secure TLS communication. However, due to a vulnerability in the SHA Authentication scheme, an attacker is able to gain unauthorized access and complete the authentication process. Subsequently, the client can execute data management protocol commands on the authenticated connection. By using crafted input parameters in one of these commands, an attacker can access an arbitrary file on the system using System privileges.
CVSS Score
8.1
EPSS Score
0.02
Published
2021-03-01
CVE-2021-27877
Known exploited
An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authentication is one of these. This authentication scheme is no longer used in current versions of the product, but hadn't yet been disabled. An attacker could remotely exploit this scheme to gain unauthorized access to an Agent and execute privileged commands.
CVSS Score
8.2
EPSS Score
0.294
Published
2021-03-01
CVE-2021-27878
Known exploited
An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a secure TLS communication. However, due to a vulnerability in the SHA Authentication scheme, an attacker is able to gain unauthorized access and complete the authentication process. Subsequently, the client can execute data management protocol commands on the authenticated connection. The attacker could use one of these commands to execute an arbitrary command on the system using system privileges.
CVSS Score
8.8
EPSS Score
0.069
Published
2021-03-01
EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted LaTeX input to a cgi/latex2png?latex= URI.
CVSS Score
9.8
EPSS Score
0.035
Published
2021-03-01
EPrints 3.4.2 exposes a reflected XSS opportunity in the via a cgi/cal URI.
CVSS Score
6.1
EPSS Score
0.664
Published
2021-03-01
SRS Policy Manager 6.X is affected by an XML External Entity Injection (XXE) vulnerability due to a misconfigured XML parser that processes user-supplied DTD input without sufficient validation. A remote unauthenticated attacker can potentially exploit this vulnerability to read system files as a non-root user and may be able to temporarily disrupt the ESRS service.
CVSS Score
7.2
EPSS Score
0.004
Published
2021-03-01
Cross Site Scripting (XSS) vulnerability in contactus.php in Doctor Appointment System 1.0 allows remote attackers to inject arbitrary web script or HTML via the comment parameter.
CVSS Score
6.1
EPSS Score
0.003
Published
2021-03-01
Cross Site Scripting (XSS) vulnerability in contactus.php in Doctor Appointment System 1.0 allows remote attackers to inject arbitrary web script or HTML via the lastname parameter.
CVSS Score
6.1
EPSS Score
0.004
Published
2021-03-01


Contact Us

Shodan ® - All rights reserved