Skip to content
Noroxi

nchsoftware records

34 published records for vendor nchsoftware.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

34 records
  • In NCH Express Invoice 7.25, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such as

    HighCVSS 8.8No exploitEPSS 2%

    nchsoftware · express invoiceApr 7, 2020

  • NCH IVM Attendant v5.12 and earlier suffers from a directory traversal weakness upon uploading plugins in a ZIP archive.

    HighCVSS 8.8No exploitEPSS 2%

    nchsoftware · ivm attendantJul 25, 2021

  • In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via documentdelete?file=/..

    HighCVSS 8.1No exploitEPSS 2%

    nchsoftware · quorumJul 25, 2021

  • NCH IVM Attendant v5.12 and earlier allows path traversal via the logdeleteselected check0 parameter for file deletion.

    HighCVSS 8.1No exploitEPSS 1%

    nchsoftware · ivm attendantJul 25, 2021

  • NCH Express Invoice 7.25 allows local users to discover the cleartext password by reading the configuration file.

    HighCVSS 7.8Proof of conceptEPSS 1%

    nchsoftware · express invoiceApr 7, 2020

  • CVE-2010-5220
    27Monitor

    Untrusted search path vulnerability in MEO Encryption Software 2.02 allows local users to gain privileges via a Trojan horse dwmapi.dll file

    MediumCVSS 6.9No exploitEPSS 0%

    nchsoftware · meo encryption softwareSep 6, 2012

  • In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via logprop?file=/..

    MediumCVSS 6.5No exploitEPSS 1%

    nchsoftware · quorumJul 25, 2021

  • NCH IVM Attendant v5.12 and earlier allows path traversal via viewfile?file=/..

    MediumCVSS 6.5No exploitEPSS 1%

    nchsoftware · ivm attendantJul 25, 2021

  • In NCH Express Accounts 8.24 and earlier, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functional

    MediumCVSS 6.5No exploitEPSS 1%

    nchsoftware · express accountsDec 28, 2020

  • NCH Express Accounts 8.24 and earlier allows local users to discover the cleartext password by reading the configuration file.

    MediumCVSS 5.5No exploitEPSS 0%

    nchsoftware · express accountsDec 28, 2020

  • Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /msglist?mbx= (reflected).

    MediumCVSS 5.4No exploitEPSS 1%

    nchsoftware · ivm attendantJul 25, 2021

  • Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the SipRule field (stored).

    MediumCVSS 5.4No exploitEPSS 1%

    nchsoftware · axon pbxJul 25, 2021

  • Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the primary phone field (stored).

    MediumCVSS 5.4No exploitEPSS 1%

    nchsoftware · axon pbxJul 25, 2021

  • Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the customer name field (stored).

    MediumCVSS 5.4No exploitEPSS 1%

    nchsoftware · axon pbxJul 25, 2021

  • In NCH Quorum v2.03 and earlier, XSS exists via User Display Name (stored).

    MediumCVSS 5.4No exploitEPSS 1%

    nchsoftware · quorumJul 25, 2021

  • In NCH Quorum v2.03 and earlier, XSS exists via /uploaddoc?id= (reflected).

    MediumCVSS 5.4No exploitEPSS 1%

    nchsoftware · quorumJul 25, 2021

  • Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /ogmprop?id= (reflected).

    MediumCVSS 5.4No exploitEPSS 1%

    nchsoftware · ivm attendantJul 25, 2021

  • Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /ipblacklist?errorip= (reflected).

    MediumCVSS 5.4No exploitEPSS 1%

    nchsoftware · axon pbxJul 25, 2021

  • In NCH Quorum v2.03 and earlier, XSS exists via Conference Description (stored).

    MediumCVSS 5.4No exploitEPSS 1%

    nchsoftware · quorumJul 25, 2021

  • Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the extension name (stored).

    MediumCVSS 5.4No exploitEPSS 1%

    nchsoftware · axon pbxJul 25, 2021

  • Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the line name (stored).

    MediumCVSS 5.4No exploitEPSS 1%

    nchsoftware · axon pbxJul 25, 2021

  • Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the outbound dialing plan (stored).

    MediumCVSS 5.4No exploitEPSS 1%

    nchsoftware · axon pbxJul 25, 2021

  • Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the blacklist IP address (stored).

    MediumCVSS 5.4No exploitEPSS 1%

    nchsoftware · axon pbxJul 25, 2021

  • In NCH Quorum v2.03 and earlier, XSS exists via /conference?id= (reflected).

    MediumCVSS 5.4No exploitEPSS 1%

    nchsoftware · quorumJul 25, 2021

  • In NCH Quorum v2.03 and earlier, XSS exists via /conferencebrowseuploadfile?confid= (reflected).

    MediumCVSS 5.4No exploitEPSS 1%

    nchsoftware · quorumJul 25, 2021