Pmb Services

Pmb

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.19%
  • Veröffentlicht 16.01.2025 13:15:07
  • Zuletzt bearbeitet 07.05.2025 16:24:03

Information exposure in the PMB platform affecting versions 4.2.13 and earlier. This vulnerability allows an attacker to upload a file to the environment and enumerate the internal files of a machine by looking at the request response.

  • EPSS 0.13%
  • Veröffentlicht 16.01.2025 13:15:07
  • Zuletzt bearbeitet 07.05.2025 16:23:45

Vulnerability in the PMB platform that allows an attacker to persist temporary files on the server, affecting versions 4.0.10 and above. This vulnerability exists in the file upload functionality on the ‘/pmb/authorities/import/iimport_authorities’ e...

  • EPSS 0.17%
  • Veröffentlicht 16.01.2025 13:15:06
  • Zuletzt bearbeitet 07.05.2025 16:24:19

Unrestricted file upload vulnerability in the PMB platform, affecting versions 4.0.10 and above. This vulnerability could allow an attacker to upload a file to gain remote access to the machine, being able to access, modify and execute commands freel...

  • EPSS 0.19%
  • Veröffentlicht 27.05.2024 07:15:08
  • Zuletzt bearbeitet 21.11.2024 09:02:18

Deserialization of Untrusted Data vulnerability in PMB Services PMB allows Remote Code Inclusion.This issue affects PMB: from 7.5.1 before 7.5.6-2, from 7.4.1 before 7.4.9, from 7.3.1 before 7.3.18.

Exploit
  • EPSS 1.27%
  • Veröffentlicht 21.02.2024 21:15:08
  • Zuletzt bearbeitet 25.03.2025 16:52:50

SQL Injection vulnerability in PMB Services PMB v.7.4.7 and before allows a remote unauthenticated attacker to execute arbitrary code via the query parameter in the /admin/convert/export_z3950.php endpoint.

Exploit
  • EPSS 0.71%
  • Veröffentlicht 02.01.2015 20:59:17
  • Zuletzt bearbeitet 12.04.2025 10:46:40

SQL injection vulnerability in classes/mono_display.class.php in PMB 4.1.3 and earlier allows remote authenticated users to execute arbitrary SQL commands via the id parameter to catalog.php.