CVE-2018-1000869
- EPSS 1.79%
- Veröffentlicht 20.12.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:40:32
phpIPAM version 1.3.2 contains a CWE-89 vulnerability in /app/admin/nat/item-add-submit.php that can result in SQL Injection.. This attack appear to be exploitable via Rough user, exploiting the vulnerability to access information he/she does not hav...
CVE-2018-1000860
- EPSS 0.8%
- Veröffentlicht 20.12.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:40:30
phpipam version 1.3.2 and earlier contains a Cross Site Scripting (XSS) vulnerability in The value of the phpipamredirect cookie is copied into an HTML tag on the login page encapsulated in single quotes. Editing the value of the cookie to r5zkh'><sc...
CVE-2018-10329
- EPSS 0.84%
- Veröffentlicht 24.04.2018 06:29:00
- Zuletzt bearbeitet 21.11.2024 03:41:14
app/tools/mac-lookup/index.php in phpIPAM 1.3.1 has Reflected XSS on /tools/mac-lookup/ via the mac parameter.
CVE-2017-15640
- EPSS 0.7%
- Veröffentlicht 21.04.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:14:56
app/sections/user-menu.php in phpIPAM before 1.3.1 has XSS via the ip parameter.
CVE-2017-6481
- EPSS 0.71%
- Veröffentlicht 05.03.2017 20:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Multiple Cross-Site Scripting (XSS) issues were discovered in phpipam 1.2. The vulnerabilities exist due to insufficient filtration of user-supplied data passed to several pages (instructions in app/admin/instructions/preview.php; subnetId in app/adm...
CVE-2015-6529
- EPSS 2.43%
- Veröffentlicht 20.08.2015 20:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
Multiple cross-site scripting (XSS) vulnerabilities in phpipam 1.1.010 allow remote attackers to inject arbitrary web script or HTML via the (1) section parameter to site/error.php or (2) ip parameter to site/tools/searchResults.php.