CVE-2019-16695
- EPSS 1.04%
- Veröffentlicht 22.09.2019 15:15:14
- Zuletzt bearbeitet 21.11.2024 04:30:59
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter.php table parameter when action=add is used.
CVE-2019-16694
- EPSS 0.76%
- Veröffentlicht 22.09.2019 15:15:13
- Zuletzt bearbeitet 21.11.2024 04:30:59
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit-result.php table parameter when action=add is used.
CVE-2019-16693
- EPSS 15.88%
- Veröffentlicht 22.09.2019 15:15:13
- Zuletzt bearbeitet 16.04.2025 15:15:44
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/order.php table parameter when action=add is used.
CVE-2019-16692
- EPSS 16.28%
- Veröffentlicht 22.09.2019 15:15:13
- Zuletzt bearbeitet 21.11.2024 04:30:59
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is used.
CVE-2019-1000010
- EPSS 0.22%
- Veröffentlicht 04.02.2019 21:29:01
- Zuletzt bearbeitet 21.11.2024 04:17:40
phpIPAM version 1.3.2 and earlier contains a Cross Site Scripting (XSS) vulnerability in subnet-scan-telnet.php that can result in executing code in victims browser. This attack appears to be exploitable via victim visits link crafted by an attacker....
CVE-2018-1000870
- EPSS 0.34%
- Veröffentlicht 20.12.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:40:32
PHPipam version 1.3.2 and earlier contains a CWE-79 vulnerability in /app/admin/users/print-user.php that can result in Execute code in the victims browser. This attack appear to be exploitable via Attacker change theme parameter in user settings. Ad...
CVE-2018-1000869
- EPSS 0.28%
- Veröffentlicht 20.12.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:40:32
phpIPAM version 1.3.2 contains a CWE-89 vulnerability in /app/admin/nat/item-add-submit.php that can result in SQL Injection.. This attack appear to be exploitable via Rough user, exploiting the vulnerability to access information he/she does not hav...
CVE-2018-1000860
- EPSS 0.16%
- Veröffentlicht 20.12.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:40:30
phpipam version 1.3.2 and earlier contains a Cross Site Scripting (XSS) vulnerability in The value of the phpipamredirect cookie is copied into an HTML tag on the login page encapsulated in single quotes. Editing the value of the cookie to r5zkh'><sc...
CVE-2018-10329
- EPSS 0.24%
- Veröffentlicht 24.04.2018 06:29:00
- Zuletzt bearbeitet 21.11.2024 03:41:14
app/tools/mac-lookup/index.php in phpIPAM 1.3.1 has Reflected XSS on /tools/mac-lookup/ via the mac parameter.
CVE-2017-15640
- EPSS 0.21%
- Veröffentlicht 21.04.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:14:56
app/sections/user-menu.php in phpIPAM before 1.3.1 has XSS via the ip parameter.