CVE-2022-31126
- EPSS 40.98%
- Veröffentlicht 06.07.2022 18:15:19
- Zuletzt bearbeitet 21.11.2024 07:03:57
Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unauthenticated attacker to code execution by sending a specially crafted HTTP request to /app/options.py ...
CVE-2022-31125
- EPSS 15.93%
- Veröffentlicht 06.07.2022 18:15:19
- Zuletzt bearbeitet 21.11.2024 07:03:56
Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unauthenticated attacker to bypass authentication and access admin functionality by sending a specially cr...
CVE-2021-38167
- EPSS 1.29%
- Veröffentlicht 07.08.2021 18:15:07
- Zuletzt bearbeitet 21.11.2024 06:16:32
Roxy-WI through 5.2.2.0 allows SQL Injection via check_login. An unauthenticated attacker can extract a valid uuid to bypass authentication.
CVE-2021-38169
- EPSS 1.53%
- Veröffentlicht 07.08.2021 18:15:07
- Zuletzt bearbeitet 21.11.2024 06:16:33
Roxy-WI through 5.2.2.0 allows command injection via /app/funct.py and /api/api_funct.py.
CVE-2021-38168
- EPSS 0.94%
- Veröffentlicht 07.08.2021 18:15:07
- Zuletzt bearbeitet 21.11.2024 06:16:32
Roxy-WI through 5.2.2.0 allows authenticated SQL injection via select_servers.