Vulnerabilities
Vulnerable Software
Xymon:  >> Xymon  >> 4.3.12  Security Vulnerabilities
xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote authenticated users to execute arbitrary commands via shell metacharacters in the adduser_name argument in (1) web/useradm.c or (2) web/chpasswd.c.
CVSS Score
8.8
EPSS Score
0.66
Published
2016-04-13
xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to read arbitrary files in the configuration directory via a "config" command.
CVSS Score
7.5
EPSS Score
0.68
Published
2016-04-13
Multiple buffer overflows in xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a long filename, involving handling a "config" command.
CVSS Score
9.8
EPSS Score
0.029
Published
2016-04-13


Contact Us

Shodan ® - All rights reserved