Vulnerabilities
Vulnerable Software
Agentejo:  >> Cockpit  Security Vulnerabilities
Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository cockpit-hq/cockpit prior to 2.2.2.
CVSS Score
9.8
EPSS Score
0.015
Published
2022-08-15
Insufficient Session Expiration in GitHub repository cockpit-hq/cockpit prior to 2.2.0.
CVSS Score
8.6
EPSS Score
0.011
Published
2022-08-08
Cockpit before 0.6.1 allows an attacker to inject custom PHP code and achieve Remote Command Execution via registerCriteriaFunction in lib/MongoLite/Database.php, as demonstrated by values in JSON data to the /auth/check or /auth/requestreset URI.
CVSS Score
9.8
EPSS Score
0.911
Published
2021-01-08
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php check function.
CVSS Score
9.8
EPSS Score
0.939
Published
2020-12-30
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function.
CVSS Score
9.8
EPSS Score
0.94
Published
2020-12-30
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function.
CVSS Score
9.8
EPSS Score
0.932
Published
2020-12-30
An issue was discovered in Agentejo Cockpit 0.10.2. Insufficient sanitization of the to parameter in the /auth/login route allows for injection of arbitrary JavaScript code into a web page's content, creating a Reflected XSS attack vector.
CVSS Score
6.1
EPSS Score
0.016
Published
2020-06-17
Agentejo Cockpit has multiple Cross-Site Scripting vulnerabilities.
CVSS Score
6.1
EPSS Score
0.002
Published
2018-10-15
Agentejo Cockpit lacks an anti-CSRF protection mechanism. Thus, an attacker is able to change API tokens, passwords, etc.
CVSS Score
8.8
EPSS Score
0.001
Published
2018-10-15
Agentejo Cockpit performs actions on files without appropriate validation and therefore allows an attacker to traverse the file system to unintended locations and/or access arbitrary files, aka /media/api Directory Traversal.
CVSS Score
9.8
EPSS Score
0.004
Published
2018-10-15


Contact Us

Shodan ® - All rights reserved