CVE-2017-15917
- EPSS 0.16%
- Veröffentlicht 26.10.2017 17:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Paessler PRTG Network Monitor 17.3.33.2830, it's possible to create a Map as a read-only user, by forging a request and sending it to the server.
CVE-2017-15651
- EPSS 0.58%
- Veröffentlicht 20.10.2017 00:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
PRTG Network Monitor 17.3.33.2830 allows remote authenticated administrators to execute arbitrary code by uploading a .exe file and then proceeding in spite of the error message.
CVE-2017-15360
- EPSS 0.19%
- Veröffentlicht 15.10.2017 17:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
PRTG Network Monitor version 17.3.33.2830 is vulnerable to stored Cross-Site Scripting on all group names created, related to incorrect error handling for an HTML encoded script.
CVE-2017-15009
- EPSS 0.3%
- Veröffentlicht 04.10.2017 01:29:03
- Zuletzt bearbeitet 20.04.2025 01:37:25
PRTG Network Monitor version 17.3.33.2830 is vulnerable to reflected Cross-Site Scripting on error.htm (the error page), via the errormsg parameter.
CVE-2017-15008
- EPSS 0.22%
- Veröffentlicht 04.10.2017 01:29:03
- Zuletzt bearbeitet 20.04.2025 01:37:25
PRTG Network Monitor version 17.3.33.2830 is vulnerable to stored Cross-Site Scripting on all sensor titles, related to incorrect error handling for a %00 in the SRC attribute of an IMG element.
CVE-2017-12879
- EPSS 0.28%
- Veröffentlicht 24.08.2017 19:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cross-site scripting (XSS-STORED) vulnerability in the DEVICES OR SENSORS functionality in Paessler PRTG Network Monitor before 17.3.33.2654 allows authenticated remote attackers to inject arbitrary web script or HTML.
CVE-2017-9816
- EPSS 0.25%
- Veröffentlicht 18.08.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cross-site scripting (XSS) vulnerability in Paessler PRTG Network Monitor before 17.2.32.2279 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2016-5078
- EPSS 0.24%
- Veröffentlicht 10.04.2017 03:59:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
Paessler PRTG before 16.2.24.4045 has XSS via SNMP.
CVE-2015-7743
- EPSS 0.32%
- Veröffentlicht 23.01.2017 21:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
XML external entity vulnerability in PRTG Network Monitor before 16.2.23.3077/3078 allows remote authenticated users to read arbitrary files by creating a new HTTP XML/REST Value sensor that accesses a crafted XML file.