CVE-2021-35438
- EPSS 1.02%
- Veröffentlicht 23.06.2021 15:15:08
- Zuletzt bearbeitet 13.02.2026 17:16:09
phpIPAM 1.4.3 allows Reflected XSS via app/dashboard/widgets/ipcalc-result.php and app/tools/ip-calculator/result.php of the IP calculator.
CVE-2020-13225
- EPSS 0.61%
- Veröffentlicht 20.05.2020 04:15:10
- Zuletzt bearbeitet 21.11.2024 05:00:50
phpIPAM 1.4 contains a stored cross site scripting (XSS) vulnerability within the Edit User Instructions field of the User Instructions widget.
CVE-2020-7988
- EPSS 0.73%
- Veröffentlicht 04.03.2020 17:15:11
- Zuletzt bearbeitet 21.11.2024 05:38:08
An issue was discovered in tools/pass-change/result.php in phpIPAM 1.4. CSRF can be used to change the password of any user/admin, to escalate privileges, and to gain access to more data and functionality. This issue exists due to the lack of a requi...
CVE-2019-16696
- EPSS 1.88%
- Veröffentlicht 22.09.2019 15:15:14
- Zuletzt bearbeitet 21.11.2024 04:31:00
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit.php table parameter when action=add is used.
CVE-2019-16695
- EPSS 1.88%
- Veröffentlicht 22.09.2019 15:15:14
- Zuletzt bearbeitet 21.11.2024 04:30:59
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter.php table parameter when action=add is used.
CVE-2019-16694
- EPSS 1.88%
- Veröffentlicht 22.09.2019 15:15:13
- Zuletzt bearbeitet 21.11.2024 04:30:59
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit-result.php table parameter when action=add is used.
CVE-2019-16693
- EPSS 4.34%
- Veröffentlicht 22.09.2019 15:15:13
- Zuletzt bearbeitet 16.04.2025 15:15:44
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/order.php table parameter when action=add is used.
CVE-2019-16692
- EPSS 10.32%
- Veröffentlicht 22.09.2019 15:15:13
- Zuletzt bearbeitet 21.11.2024 04:30:59
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is used.
CVE-2019-1000010
- EPSS 0.86%
- Veröffentlicht 04.02.2019 21:29:01
- Zuletzt bearbeitet 21.11.2024 04:17:40
phpIPAM version 1.3.2 and earlier contains a Cross Site Scripting (XSS) vulnerability in subnet-scan-telnet.php that can result in executing code in victims browser. This attack appears to be exploitable via victim visits link crafted by an attacker....
CVE-2018-1000870
- EPSS 0.95%
- Veröffentlicht 20.12.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:40:32
PHPipam version 1.3.2 and earlier contains a CWE-79 vulnerability in /app/admin/users/print-user.php that can result in Execute code in the victims browser. This attack appear to be exploitable via Attacker change theme parameter in user settings. Ad...