Phpipam

Phpipam

56 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.02%
  • Veröffentlicht 23.06.2021 15:15:08
  • Zuletzt bearbeitet 13.02.2026 17:16:09

phpIPAM 1.4.3 allows Reflected XSS via app/dashboard/widgets/ipcalc-result.php and app/tools/ip-calculator/result.php of the IP calculator.

Exploit
  • EPSS 0.61%
  • Veröffentlicht 20.05.2020 04:15:10
  • Zuletzt bearbeitet 21.11.2024 05:00:50

phpIPAM 1.4 contains a stored cross site scripting (XSS) vulnerability within the Edit User Instructions field of the User Instructions widget.

Exploit
  • EPSS 0.73%
  • Veröffentlicht 04.03.2020 17:15:11
  • Zuletzt bearbeitet 21.11.2024 05:38:08

An issue was discovered in tools/pass-change/result.php in phpIPAM 1.4. CSRF can be used to change the password of any user/admin, to escalate privileges, and to gain access to more data and functionality. This issue exists due to the lack of a requi...

Exploit
  • EPSS 1.88%
  • Veröffentlicht 22.09.2019 15:15:14
  • Zuletzt bearbeitet 21.11.2024 04:31:00

phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit.php table parameter when action=add is used.

Exploit
  • EPSS 1.88%
  • Veröffentlicht 22.09.2019 15:15:14
  • Zuletzt bearbeitet 21.11.2024 04:30:59

phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter.php table parameter when action=add is used.

Exploit
  • EPSS 1.88%
  • Veröffentlicht 22.09.2019 15:15:13
  • Zuletzt bearbeitet 21.11.2024 04:30:59

phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit-result.php table parameter when action=add is used.

Exploit
  • EPSS 4.34%
  • Veröffentlicht 22.09.2019 15:15:13
  • Zuletzt bearbeitet 16.04.2025 15:15:44

phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/order.php table parameter when action=add is used.

Exploit
  • EPSS 10.32%
  • Veröffentlicht 22.09.2019 15:15:13
  • Zuletzt bearbeitet 21.11.2024 04:30:59

phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is used.

Exploit
  • EPSS 0.86%
  • Veröffentlicht 04.02.2019 21:29:01
  • Zuletzt bearbeitet 21.11.2024 04:17:40

phpIPAM version 1.3.2 and earlier contains a Cross Site Scripting (XSS) vulnerability in subnet-scan-telnet.php that can result in executing code in victims browser. This attack appears to be exploitable via victim visits link crafted by an attacker....

Exploit
  • EPSS 0.95%
  • Veröffentlicht 20.12.2018 17:29:00
  • Zuletzt bearbeitet 21.11.2024 03:40:32

PHPipam version 1.3.2 and earlier contains a CWE-79 vulnerability in /app/admin/users/print-user.php that can result in Execute code in the victims browser. This attack appear to be exploitable via Attacker change theme parameter in user settings. Ad...