CVE-2023-33336
- EPSS 0.03%
- Veröffentlicht 30.06.2023 02:15:09
- Zuletzt bearbeitet 21.11.2024 08:05:26
Reflected cross site scripting (XSS) vulnerability was discovered in Sophos Web Appliance v4.3.9.1 that allows for arbitrary code to be inputted via the double quotes.
CVE-2020-36692
- EPSS 0.2%
- Veröffentlicht 04.04.2023 10:15:07
- Zuletzt bearbeitet 11.02.2025 15:15:14
A reflected XSS via POST vulnerability in report scheduler of Sophos Web Appliance versions older than 4.3.10.4 allows execution of JavaScript code in the victim browser via a malicious form that must be manually submitted by the victim while logged ...
CVE-2022-4934
- EPSS 0.15%
- Veröffentlicht 04.04.2023 10:15:07
- Zuletzt bearbeitet 11.02.2025 15:15:15
A post-auth command injection vulnerability in the exception wizard of Sophos Web Appliance older than version 4.3.10.4 allows administrators to execute arbitrary code.
CVE-2023-1671
- EPSS 94.3%
- Veröffentlicht 04.04.2023 10:15:07
- Zuletzt bearbeitet 27.10.2025 17:00:49
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitrary code.
CVE-2017-9523
- EPSS 0.12%
- Veröffentlicht 09.06.2017 00:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The Sophos Web Appliance before 4.3.2 has XSS in the FTP redirect page, aka NSWA-1342.
CVE-2017-6182
- EPSS 14.26%
- Veröffentlicht 30.03.2017 17:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote command injection via functions, aka NSWA-1304.
CVE-2017-6183
- EPSS 2.57%
- Veröffentlicht 30.03.2017 17:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's configuration utilities for adding (and detecting) Active Directory servers was vulnerable to remote command injection, aka NSWA-1314.
CVE-2017-6184
- EPSS 1.16%
- Veröffentlicht 30.03.2017 17:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote command injection via the token parameter, aka NSWA-1303.
CVE-2017-6412
- EPSS 0.74%
- Veröffentlicht 30.03.2017 17:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Sophos Web Appliance (SWA) before 4.3.1.2, Session Fixation could occur, aka NSWA-1310.
- EPSS 6.75%
- Veröffentlicht 28.01.2017 12:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The Sophos Web Appliance (version 4.2.1.3) is vulnerable to two Remote Command Injection vulnerabilities affecting its web administrative interface. These vulnerabilities occur in the MgrReport.php (/controllers/MgrReport.php) component responsible f...