CVE-2021-35223
- EPSS 2.94%
- Veröffentlicht 31.08.2021 16:15:07
- Zuletzt bearbeitet 21.11.2024 06:12:05
The Serv-U File Server allows for events such as user login failures to be audited by executing a command. This command can be supplied with parameters that can take the form of user string variables, allowing remote code execution.
- EPSS 91.16%
- Veröffentlicht 14.07.2021 21:15:08
- Zuletzt bearbeitet 27.10.2025 17:01:30
Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability. If exploited, a threat actor may be able to gain privileged access to the machine hosting Serv-U Only. S...
CVE-2021-32604
- EPSS 1.72%
- Veröffentlicht 11.05.2021 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:07:21
Share/IncomingWizard.htm in SolarWinds Serv-U before 15.2.3 mishandles the user-supplied SenderEmail parameter, aka "Share URL XSS."
CVE-2021-3154
- EPSS 1.24%
- Veröffentlicht 04.05.2021 14:15:08
- Zuletzt bearbeitet 21.11.2024 06:21:00
An issue was discovered in SolarWinds Serv-U before 15.2.2. Unauthenticated attackers can retrieve cleartext passwords via macro Injection. NOTE: this had a distinct fix relative to CVE-2020-35481.
CVE-2021-25276
- EPSS 0.47%
- Veröffentlicht 03.02.2021 17:15:16
- Zuletzt bearbeitet 21.11.2024 05:54:39
In SolarWinds Serv-U before 15.2.2 Hotfix 1, there is a directory containing user profile files (that include users' password hashes) that is world readable and writable. An unprivileged Windows user (having access to the server's filesystem) can add...
CVE-2020-35482
- EPSS 1.52%
- Veröffentlicht 03.02.2021 16:15:14
- Zuletzt bearbeitet 21.11.2024 05:27:23
SolarWinds Serv-U before 15.2.2 allows authenticated reflected XSS.
CVE-2020-35481
- EPSS 1.3%
- Veröffentlicht 03.02.2021 16:15:14
- Zuletzt bearbeitet 21.11.2024 05:27:23
SolarWinds Serv-U before 15.2.2 allows Unauthenticated Macro Injection.
CVE-2020-28001
- EPSS 3.79%
- Veröffentlicht 03.02.2021 16:15:13
- Zuletzt bearbeitet 21.11.2024 05:22:10
SolarWinds Serv-U before 15.2.2 allows Authenticated Stored XSS.
CVE-2020-27994
- EPSS 3.93%
- Veröffentlicht 03.02.2021 16:15:13
- Zuletzt bearbeitet 21.11.2024 05:22:10
SolarWinds Serv-U before 15.2.2 allows Authenticated Directory Traversal.
CVE-2020-15576
- EPSS 1.55%
- Veröffentlicht 07.07.2020 14:15:11
- Zuletzt bearbeitet 21.11.2024 05:05:46
SolarWinds Serv-U File Server before 15.2.1 allows information disclosure via an HTTP response.