Roxy-wi

Roxy-wi

35 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.37%
  • Veröffentlicht 10.06.2026 14:00:54
  • Zuletzt bearbeitet 10.06.2026 19:37:41

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, POST /waf/<service>/<server_ip>/rule/<rule_id>/save accepts a config_file_name form field that is passed straight through to config_...

  • EPSS 0.2%
  • Veröffentlicht 10.06.2026 14:00:06
  • Zuletzt bearbeitet 10.06.2026 19:37:41

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, PUT /smon/check (app/routes/smon/routes.py:117-138) gates only on roxywi_common.check_user_group_for_flask() — which validates that ...

  • EPSS 0.2%
  • Veröffentlicht 10.06.2026 13:59:41
  • Zuletzt bearbeitet 10.06.2026 19:37:41

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, agent_action (app/routes/smon/agent_routes.py:166-179) has decorators @bp.post('/agent/action/<action>') and @jwt_required() only — ...

  • EPSS 0.27%
  • Veröffentlicht 10.06.2026 13:59:24
  • Zuletzt bearbeitet 10.06.2026 19:37:41

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the install blueprint declares only bp.before_request → @jwt_required() (app/routes/install/routes.py:36-39). The individual endpoin...

Exploit
  • EPSS 0.66%
  • Veröffentlicht 24.04.2026 02:10:13
  • Zuletzt bearbeitet 27.04.2026 15:16:15

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the /config/ < service > /find-in-config endpoint in Roxy-WI fails to sanitize the user-supplied words parameter before embedding it into...

Exploit
  • EPSS 0.35%
  • Veröffentlicht 24.04.2026 02:05:02
  • Zuletzt bearbeitet 27.04.2026 15:10:14

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 8.2.6.4 have a SQL injection vulnerability in the haproxy_section_save function in app/routes/config/routes.py. The server_ip parameter, sourced ...

Exploit
  • EPSS 0.43%
  • Veröffentlicht 24.04.2026 01:55:43
  • Zuletzt bearbeitet 27.04.2026 15:04:44

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the oldconfig parameter in the haproxy_section_save interface has an arbitrary file read vulnerability. Version 8.2.6.4 fixes the issue.

Exploit
  • EPSS 0.82%
  • Veröffentlicht 24.04.2026 01:52:47
  • Zuletzt bearbeitet 27.04.2026 15:03:04

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the haproxy_section_save interface presents a vulnerability that could lead to remote code execution due to path traversal and writing in...

Exploit
  • EPSS 0.42%
  • Veröffentlicht 20.04.2026 20:26:52
  • Zuletzt bearbeitet 24.04.2026 19:18:10

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions up to and including 8.2.8.2, when LDAP authentication is enabled, Roxy-WI constructs an LDAP search filter by directly concatenating the user-supplied ...

Exploit
  • EPSS 0.39%
  • Veröffentlicht 20.04.2026 20:24:15
  • Zuletzt bearbeitet 24.04.2026 19:19:26

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the POST /config/<service>/show API endpoint accepts a configver parameter that is directly appended to a base directory path to construc...