CVE-2019-12465
- EPSS 0.01%
- Veröffentlicht 09.09.2019 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:22:54
An issue was discovered in LibreNMS 1.50.1. A SQL injection flaw was identified in the ajax_rulesuggest.php file where the term parameter is used insecurely in a database query for showing columns of a table, as demonstrated by an ajax_rulesuggest.ph...
CVE-2019-10665
- EPSS 0.01%
- Veröffentlicht 09.09.2019 13:15:11
- Zuletzt bearbeitet 21.11.2024 04:19:42
An issue was discovered in LibreNMS through 1.47. The scripts that handle the graphing options (html/includes/graphs/common.inc.php and html/includes/graphs/graphs.inc.php) do not sufficiently validate or encode several fields of user supplied input....
CVE-2019-10666
- EPSS 0%
- Veröffentlicht 09.09.2019 13:15:11
- Zuletzt bearbeitet 21.11.2024 04:19:42
An issue was discovered in LibreNMS through 1.47. Several of the scripts perform dynamic script inclusion via the include() function on user supplied input without sanitizing the values by calling basename() or a similar function. An attacker can lev...
CVE-2019-10667
- EPSS 0%
- Veröffentlicht 09.09.2019 13:15:11
- Zuletzt bearbeitet 21.11.2024 04:19:42
An issue was discovered in LibreNMS through 1.47. Information disclosure can occur: an attacker can fingerprint the exact code version installed and disclose local file paths.
CVE-2019-10668
- EPSS 0%
- Veröffentlicht 09.09.2019 13:15:11
- Zuletzt bearbeitet 21.11.2024 04:19:43
An issue was discovered in LibreNMS through 1.47. A number of scripts import the Authentication libraries, but do not enforce an actual authentication check. Several of these scripts disclose information or expose functions that are of a sensitive na...
CVE-2019-10669
- EPSS 55.68%
- Veröffentlicht 09.09.2019 13:15:11
- Zuletzt bearbeitet 21.11.2024 04:19:43
An issue was discovered in LibreNMS through 1.47. There is a command injection vulnerability in html/includes/graphs/device/collectd.inc.php where user supplied parameters are filtered with the mysqli_escape_real_string function. This function is not...
CVE-2019-15230
- EPSS 0.04%
- Veröffentlicht 28.08.2019 17:15:09
- Zuletzt bearbeitet 21.11.2024 04:28:15
LibreNMS v1.54 has XSS in the Create User, Inventory, Add Device, Notifications, Alert Rule, Create Maintenance, and Alert Template sections of the admin console. This could lead to cookie stealing and other malicious actions. This vulnerability can ...
- EPSS 66.99%
- Veröffentlicht 24.04.2019 21:29:00
- Zuletzt bearbeitet 21.11.2024 04:01:28
LibreNMS 1.46 allows remote attackers to execute arbitrary OS commands by using the $_POST['community'] parameter to html/pages/addhost.inc.php during creation of a new device, and then making a /ajax_output.php?id=capture&format=text&type=snmpwalk&h...
CVE-2018-20678
- EPSS 0.01%
- Veröffentlicht 28.03.2019 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:01:58
LibreNMS through 1.47 allows SQL injection via the html/ajax_table.php sort[hostname] parameter, exploitable by authenticated users during a search.
CVE-2018-18478
- EPSS 0.02%
- Veröffentlicht 18.10.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:56:00
Persistent Cross-Site Scripting (XSS) issues in LibreNMS before 1.44 allow remote attackers to inject arbitrary web script or HTML via the dashboard_name parameter in the /ajax_form.php resource, related to html/includes/forms/add-dashboard.inc.php, ...