CVE-2025-11195
- EPSS 0.01%
- Veröffentlicht 30.09.2025 18:15:49
- Zuletzt bearbeitet 08.10.2025 14:15:51
Rapid7 AppSpider Pro versions below 7.5.021 suffer from a project name validation vulnerability, whereby an attacker can change the project name directly in the configuration file to a name that already exists. This issue stems from a lack of effecti...
CVE-2025-36857
- EPSS 0.02%
- Veröffentlicht 25.09.2025 15:16:11
- Zuletzt bearbeitet 11.12.2025 18:20:20
Rapid7 Appspider Pro versions below 7.5.021, suffer from a broken access control vulnerability in the application's configuration file loading mechanism, whereby an attacker can place files in directories belonging to other users or projects. Affecte...
CVE-2025-4951
- EPSS 0.03%
- Veröffentlicht 20.05.2025 08:39:38
- Zuletzt bearbeitet 11.12.2025 18:21:25
Editions of Rapid7 AppSpider Pro before version 7.5.018 is vulnerable to a stored cross-site scripting vulnerability in the "ScanName" field. Despite the application preventing the inclusion of special characters within the "ScanName" field, this cou...
CVE-2017-5236
- EPSS 0.26%
- Veröffentlicht 03.05.2017 16:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Editions of Rapid7 AppSpider Pro installers prior to version 6.14.060 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer.
CVE-2017-5240
- EPSS 0.39%
- Veröffentlicht 03.05.2017 16:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Editions of Rapid7 AppSpider Pro prior to version 6.14.060 contain a heap-based buffer overflow in the FLAnalyzer.exe component. A malicious or malformed Flash source file can cause a denial of service condition when parsed by this component, causing...
CVE-2017-5233
- EPSS 0.19%
- Veröffentlicht 02.03.2017 20:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Rapid7 AppSpider Pro installers prior to version 6.14.053 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer.