Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In 2018
Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "PresentSpace.jsp" has reflected XSS via the ConnPoolName and GroupId parameters.
CVSS Score
6.1
EPSS Score
0.002
Published
2018-12-17
Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "SubPagePackages.jsp" has reflected XSS via the ConnPoolName and GroupId parameters.
CVSS Score
6.1
EPSS Score
0.002
Published
2018-12-17
Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "UserProperties.jsp" has reflected XSS via the ConnPoolName parameter.
CVSS Score
6.1
EPSS Score
0.002
Published
2018-12-17
Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "Users.jsp" has reflected XSS via the ConnPoolName parameter.
CVSS Score
6.1
EPSS Score
0.002
Published
2018-12-17
Zoho ManageEngine OpManager 12.3 before 123238 allows SQL injection via the getGraphData API.
CVSS Score
9.8
EPSS Score
0.128
Published
2018-12-17
Error reporting within Rendertron 1.0.0 allows reflected Cross Site Scripting (XSS) from invalid URLs.
CVSS Score
6.1
EPSS Score
0.002
Published
2018-12-17
Rendertron 1.0.0 includes an _ah/stop route to shutdown the Chrome instance responsible for serving render requests to all users. Visiting this route with a GET request allows any unauthorized remote attacker to disable the core service of the application.
CVSS Score
7.5
EPSS Score
0.005
Published
2018-12-17
Rendertron 1.0.0 allows for alternative protocols such as 'file://' introducing a Local File Inclusion (LFI) bug where arbitrary files can be read by a remote attacker.
CVSS Score
7.5
EPSS Score
0.003
Published
2018-12-17
Installed packages are exposed by node_modules in Rendertron 1.0.0, allowing remote attackers to read absolute paths on the server by examining the "_where" attribute of package.json files.
CVSS Score
7.5
EPSS Score
0.003
Published
2018-12-17
An issue was discovered in the Linux kernel before 4.19.9. The USB subsystem mishandles size checks during the reading of an extra descriptor, related to __usb_get_extra_descriptor in drivers/usb/core/usb.c.
CVSS Score
6.8
EPSS Score
0.001
Published
2018-12-17


Contact Us

Shodan ® - All rights reserved