Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In May 2021
Incorrect Access Control in Nagios Fusion 4.1.8 and earlier allows low-privileged authenticated users to extract passwords used to manage fused servers via the test_server command in ajaxhelper.php.
CVSS Score
6.5
EPSS Score
0.074
Published
2021-05-24
Re-Logic Terraria before 1.4.2.3 performs Insecure Deserialization.
CVSS Score
9.8
EPSS Score
0.006
Published
2021-05-24
A Cross-Site Request Forgery (CSRF) vulnerability exists in ProjectWorlds College Management System Php 1.0 that allows a remote attacker to modify, delete, or make a new entry of the student, faculty, teacher, subject, scores, location, and article data.
CVSS Score
6.5
EPSS Score
0.002
Published
2021-05-24
Projectsworlds College Management System Php 1.0 is vulnerable to SQL injection issues over multiple parameters.
CVSS Score
9.8
EPSS Score
0.007
Published
2021-05-24
Projectworlds Online Examination System 1.0 is vulnerable to CSRF, which allows a remote attacker to delete the existing user.
CVSS Score
6.5
EPSS Score
0.002
Published
2021-05-24
Project Worlds Online Examination System 1.0 is affected by Cross Site Scripting (XSS) via account.php.
CVSS Score
6.1
EPSS Score
0.003
Published
2021-05-24
Insufficient Verification of Data Authenticity in Nagios Fusion 4.1.8 and earlier and Nagios XI 5.7.5 and earlier allows for Escalation of Privileges or Code Execution as root via vectors related to an untrusted update package to upgrade_to_latest.sh.
CVSS Score
9.8
EPSS Score
0.004
Published
2021-05-24
Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation or Code Execution as root via vectors related to corrupt component installation in cmd_subsys.php.
CVSS Score
9.8
EPSS Score
0.011
Published
2021-05-24
Command Injection in Nagios Fusion 4.1.8 and earlier allows Privilege Escalation from apache to root in cmd_subsys.php.
CVSS Score
9.8
EPSS Score
0.024
Published
2021-05-24
Improper input validation in Nagios Fusion 4.1.8 and earlier allows a remote attacker with control over a fused server to inject arbitrary HTML, aka XSS.
CVSS Score
6.1
EPSS Score
0.063
Published
2021-05-24


Contact Us

Shodan ® - All rights reserved