Ilevia

Eve X1 Server

9 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.95%
  • Veröffentlicht 08.12.2025 21:32:08
  • Zuletzt bearbeitet 24.02.2026 06:16:20

A vulnerability was determined in Ilevia EVE X1 Server up to 4.6.5.0.eden. Impacted is an unknown function of the file /ajax/php/leaf_search.php. This manipulation of the argument line causes command injection. The attack can be initiated remotely. A...

Exploit
  • EPSS 0.09%
  • Veröffentlicht 16.10.2025 17:56:53
  • Zuletzt bearbeitet 23.10.2025 19:16:38

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an absolute path traversal vulnerability in get_file_content.php that allows an attacker to read arbitrary files. Ilevia has declined to service this vulnerability, and recommends that cu...

  • EPSS 0.53%
  • Veröffentlicht 16.10.2025 17:56:16
  • Zuletzt bearbeitet 25.11.2025 17:15:49

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain authenticated OS command injection vulnerabilities in multiple web-accessible PHP scripts that call exec() and allow an authenticated attacker to execute arbitrary commands. Ilevia has de...

  • EPSS 0.02%
  • Veröffentlicht 16.10.2025 17:55:50
  • Zuletzt bearbeitet 06.11.2025 19:15:41

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an insecure hashing algorithm vulnerability. The product stores passwords using the MD5 hash function without applying a per‑password salt. Because MD5 is a fast, unsalted hash, an attack...

Exploit
  • EPSS 0.17%
  • Veröffentlicht 16.10.2025 17:55:29
  • Zuletzt bearbeitet 23.10.2025 19:33:42

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a reflected cross-site scripting (XSS) vulnerability in index.php that allows an unauthenticated attacker to execute arbitrary code. Ilevia has declined to service this vulnerability, and...

Exploit
  • EPSS 0.09%
  • Veröffentlicht 16.10.2025 17:55:00
  • Zuletzt bearbeitet 23.10.2025 19:13:59

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a relative path traversal vulnerability in get_file_content.php that allows an attacker to read arbitrary files. Ilevia has declined to service this vulnerability, and recommends that cus...

  • EPSS 0.16%
  • Veröffentlicht 16.10.2025 17:54:36
  • Zuletzt bearbeitet 06.11.2025 19:15:41

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an execution with unnecessary privileges vulnerability in sync_project.sh that allows an attacker to escalate privileges to root. Ilevia has declined to service this vulnerability, and re...

Exploit
  • EPSS 14.51%
  • Veröffentlicht 16.10.2025 17:53:34
  • Zuletzt bearbeitet 23.10.2025 19:28:18

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an OS command injection vulnerability in mbus_build_from_csv.php that allows an unauthenticated attacker to execute arbitrary code. Ilevia has declined to service this vulnerability, and ...

  • EPSS 0.18%
  • Veröffentlicht 16.10.2025 17:52:55
  • Zuletzt bearbeitet 03.11.2025 19:15:52

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a use of default credentials vulnerability that allows an unauthenticated attacker to obtain remote access. Ilevia has declined to service this vulnerability, and recommends that customer...