Progress

Whatsup Gold

56 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 42.25%
  • Published 11.05.2022 18:15:29
  • Last modified 21.11.2024 06:59:48

In Progress Ipswitch WhatsUp Gold 21.1.0 through 21.1.1, and 22.0.0, it is possible for an authenticated user to invoke an API transaction that would allow them to read the contents of a local file.

  • EPSS 84.04%
  • Published 11.05.2022 18:15:29
  • Last modified 21.11.2024 06:59:48

In Progress Ipswitch WhatsUp Gold 21.0.0 through 21.1.1, and 22.0.0, it is possible for an unauthenticated attacker to invoke an API transaction that would allow them to relay encrypted WhatsUp Gold user credentials to an arbitrary host.

  • EPSS 54.21%
  • Published 11.05.2022 18:15:29
  • Last modified 21.11.2024 06:59:48

In Progress Ipswitch WhatsUp Gold 17.0.0 through 21.1.1, and 22.0.0, it is possible for an authenticated user to invoke an API transaction that would allow them to read sensitive operating-system attributes from a host that is accessible by the Whats...

  • EPSS 0.07%
  • Published 01.05.2018 16:29:00
  • Last modified 21.11.2024 04:14:38

An SSRF issue was discovered in NmAPI.exe in Ipswitch WhatsUp Gold before 2018 (18.0). Malicious actors can submit specially crafted requests via the NmAPI executable to (1) gain unauthorized access to the WhatsUp Gold system, (2) obtain information ...

  • EPSS 0.21%
  • Published 01.05.2018 16:29:00
  • Last modified 21.11.2024 04:14:38

A Code Injection issue was discovered in DlgSelectMibFile.asp in Ipswitch WhatsUp Gold before 2018 (18.0). Malicious actors can inject a specially crafted SNMP MIB file that could allow them to execute arbitrary commands and code on the WhatsUp Gold ...

  • EPSS 0.11%
  • Published 24.01.2018 15:29:01
  • Last modified 21.11.2024 04:09:22

An issue was discovered in Ipswitch WhatsUp Gold before 2017 Plus SP1 (17.1.1). Multiple SQL injection vulnerabilities are present in the legacy .ASP pages, which could allow attackers to execute arbitrary SQL commands via unspecified vectors.

  • EPSS 0.1%
  • Published 24.01.2018 15:29:01
  • Last modified 21.11.2024 04:09:22

An issue was discovered in Ipswitch WhatsUp Gold before 2017 Plus SP1 (17.1.1). Remote clients can take advantage of a misconfiguration in the TFTP server that could allow attackers to execute arbitrary commands on the TFTP server via unspecified vec...

  • EPSS 0.11%
  • Published 06.10.2016 14:59:15
  • Last modified 12.04.2025 10:46:40

Ipswitch WhatsUp Gold 16.4.1 WrFreeFormText.asp sUniqueID Parameter Blind SQL Injection

  • EPSS 4.36%
  • Published 08.01.2016 02:59:04
  • Last modified 12.04.2025 10:46:40

The DroneDeleteOldMeasurements implementation in Ipswitch WhatsUp Gold before 16.4 does not properly validate serialized XML objects, which allows remote attackers to conduct SQL injection attacks via a crafted SOAP request.

Exploit
  • EPSS 0.2%
  • Published 27.12.2015 03:59:01
  • Last modified 12.04.2025 10:46:40

Multiple cross-site scripting (XSS) vulnerabilities in IPSwitch WhatsUp Gold before 16.4 allow remote attackers to inject arbitrary web script or HTML via (1) an SNMP OID object, (2) an SNMP trap message, (3) the View Names field, (4) the Group Names...