Opmantek

Open-audit

16 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.42%
  • Veröffentlicht 03.01.2022 13:15:09
  • Zuletzt bearbeitet 21.11.2024 06:31:21

An information exposure issue has been discovered in Opmantek Open-AudIT 4.2.0. The vulnerability allows an authenticated attacker to read file outside of the restricted directory.

  • EPSS 1%
  • Veröffentlicht 22.12.2021 13:15:07
  • Zuletzt bearbeitet 21.11.2024 06:24:27

An issue was discovered in Opmantek Open-AudIT after 3.5.0. Without authentication, a vulnerability in code_igniter/application/controllers/util.php allows an attacker perform command execution without echoes.

Exploit
  • EPSS 4.46%
  • Veröffentlicht 20.12.2021 12:15:07
  • Zuletzt bearbeitet 21.11.2024 06:31:41

Opmantek Open-AudIT Community 4.2.0 (Fixed in 4.3.0) is affected by a Cross Site Scripting (XSS) vulnerability. If a bad value is passed to the routine via a URL, malicious JavaScript code can be executed in the victim's browser.

  • EPSS 0.32%
  • Veröffentlicht 05.02.2021 14:15:19
  • Zuletzt bearbeitet 21.11.2024 06:21:19

Opmantek Open-AudIT 4.0.1 is affected by cross-site scripting (XSS). When outputting SQL statements for debugging, a maliciously crafted query can trigger an XSS attack. This attack only succeeds if the user is already logged in to Open-AudIT before ...

  • EPSS 0.63%
  • Veröffentlicht 20.01.2021 16:15:14
  • Zuletzt bearbeitet 21.11.2024 06:20:57

Within the Open-AudIT up to version 3.5.3 application, the web interface hides SSH secrets, Windows passwords, and SNMP strings from users using HTML 'password field' obfuscation. By using Developer tools or similar, it is possible to change the obfu...

Exploit
  • EPSS 0.39%
  • Veröffentlicht 29.04.2020 22:15:12
  • Zuletzt bearbeitet 21.11.2024 04:58:57

An issue was discovered in Open-AudIT 3.2.2. There are Multiple SQL Injections.

Exploit
  • EPSS 3.78%
  • Veröffentlicht 29.04.2020 22:15:12
  • Zuletzt bearbeitet 21.11.2024 04:58:57

An issue was discovered in Open-AudIT 3.2.2. There is Arbitrary file upload.

Exploit
  • EPSS 0.3%
  • Veröffentlicht 28.04.2020 22:15:12
  • Zuletzt bearbeitet 21.11.2024 04:59:23

Open-AudIT 3.3.0 allows an XSS attack after login.

Exploit
  • EPSS 63.67%
  • Veröffentlicht 28.04.2020 14:15:14
  • Zuletzt bearbeitet 21.11.2024 04:59:13

An issue was discovered in Open-AudIT 3.3.1. There is shell metacharacter injection via attributes to an open-audit/configuration/ URI. An attacker can exploit this by adding an excluded IP address to the global discovery settings (internally called ...

Exploit
  • EPSS 3.96%
  • Veröffentlicht 27.04.2020 17:15:13
  • Zuletzt bearbeitet 21.11.2024 04:58:56

An issue was discovered in Open-AudIT 3.2.2. There is OS Command injection in Discovery.