Solarwinds

Serv-u

55 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.94%
  • Veröffentlicht 31.08.2021 16:15:07
  • Zuletzt bearbeitet 21.11.2024 06:12:05

The Serv-U File Server allows for events such as user login failures to be audited by executing a command. This command can be supplied with parameters that can take the form of user string variables, allowing remote code execution.

Warnung Medienbericht
  • EPSS 91.16%
  • Veröffentlicht 14.07.2021 21:15:08
  • Zuletzt bearbeitet 27.10.2025 17:01:30

Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability. If exploited, a threat actor may be able to gain privileged access to the machine hosting Serv-U Only. S...

Exploit
  • EPSS 1.72%
  • Veröffentlicht 11.05.2021 23:15:08
  • Zuletzt bearbeitet 21.11.2024 06:07:21

Share/IncomingWizard.htm in SolarWinds Serv-U before 15.2.3 mishandles the user-supplied SenderEmail parameter, aka "Share URL XSS."

  • EPSS 1.24%
  • Veröffentlicht 04.05.2021 14:15:08
  • Zuletzt bearbeitet 21.11.2024 06:21:00

An issue was discovered in SolarWinds Serv-U before 15.2.2. Unauthenticated attackers can retrieve cleartext passwords via macro Injection. NOTE: this had a distinct fix relative to CVE-2020-35481.

Exploit
  • EPSS 0.47%
  • Veröffentlicht 03.02.2021 17:15:16
  • Zuletzt bearbeitet 21.11.2024 05:54:39

In SolarWinds Serv-U before 15.2.2 Hotfix 1, there is a directory containing user profile files (that include users' password hashes) that is world readable and writable. An unprivileged Windows user (having access to the server's filesystem) can add...

  • EPSS 1.52%
  • Veröffentlicht 03.02.2021 16:15:14
  • Zuletzt bearbeitet 21.11.2024 05:27:23

SolarWinds Serv-U before 15.2.2 allows authenticated reflected XSS.

  • EPSS 1.3%
  • Veröffentlicht 03.02.2021 16:15:14
  • Zuletzt bearbeitet 21.11.2024 05:27:23

SolarWinds Serv-U before 15.2.2 allows Unauthenticated Macro Injection.

Exploit
  • EPSS 3.79%
  • Veröffentlicht 03.02.2021 16:15:13
  • Zuletzt bearbeitet 21.11.2024 05:22:10

SolarWinds Serv-U before 15.2.2 allows Authenticated Stored XSS.

Exploit
  • EPSS 3.93%
  • Veröffentlicht 03.02.2021 16:15:13
  • Zuletzt bearbeitet 21.11.2024 05:22:10

SolarWinds Serv-U before 15.2.2 allows Authenticated Directory Traversal.

  • EPSS 1.55%
  • Veröffentlicht 07.07.2020 14:15:11
  • Zuletzt bearbeitet 21.11.2024 05:05:46

SolarWinds Serv-U File Server before 15.2.1 allows information disclosure via an HTTP response.