Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In May 2021
Incorrect Access Control in Nagios Fusion 4.1.8 and earlier allows low-privileged authenticated users to extract passwords used to manage fused servers via the test_server command in ajaxhelper.php.
CVSS Score
6.5
EPSS Score
0.214
Published
2021-05-24
Re-Logic Terraria before 1.4.2.3 performs Insecure Deserialization.
CVSS Score
9.8
EPSS Score
0.006
Published
2021-05-24
A Cross-Site Request Forgery (CSRF) vulnerability exists in ProjectWorlds College Management System Php 1.0 that allows a remote attacker to modify, delete, or make a new entry of the student, faculty, teacher, subject, scores, location, and article data.
CVSS Score
6.5
EPSS Score
0.002
Published
2021-05-24
Projectsworlds College Management System Php 1.0 is vulnerable to SQL injection issues over multiple parameters.
CVSS Score
9.8
EPSS Score
0.007
Published
2021-05-24
Projectworlds Online Examination System 1.0 is vulnerable to CSRF, which allows a remote attacker to delete the existing user.
CVSS Score
6.5
EPSS Score
0.003
Published
2021-05-24
Project Worlds Online Examination System 1.0 is affected by Cross Site Scripting (XSS) via account.php.
CVSS Score
6.1
EPSS Score
0.003
Published
2021-05-24
Insufficient Verification of Data Authenticity in Nagios Fusion 4.1.8 and earlier and Nagios XI 5.7.5 and earlier allows for Escalation of Privileges or Code Execution as root via vectors related to an untrusted update package to upgrade_to_latest.sh.
CVSS Score
9.8
EPSS Score
0.008
Published
2021-05-24
Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation or Code Execution as root via vectors related to corrupt component installation in cmd_subsys.php.
CVSS Score
9.8
EPSS Score
0.055
Published
2021-05-24
Command Injection in Nagios Fusion 4.1.8 and earlier allows Privilege Escalation from apache to root in cmd_subsys.php.
CVSS Score
9.8
EPSS Score
0.104
Published
2021-05-24
Improper input validation in Nagios Fusion 4.1.8 and earlier allows a remote attacker with control over a fused server to inject arbitrary HTML, aka XSS.
CVSS Score
6.1
EPSS Score
0.258
Published
2021-05-24


Contact Us

Shodan ® - All rights reserved