Openfiler records
4 published records for vendor openfiler.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-352 Cross-Site Request Forgery (CSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
28Monitor | CVE-2014-7190Proof of concept | Multiple cross-site request forgery (CSRF) vulnerabilities in Openfiler 2.99.1 allow remote attackers to hijack the authentication of adminiopenfiler · openfiler · CWE-352 | Medium6.8 | — | 2.3% | Sep 30, 2014 |
24Monitor | CVE-2011-1086No exploit | Cross-site scripting (XSS) vulnerability in admin/system.html in Openfiler 2.3 allows remote attackers to inject arbitrary web script or HTMopenfiler · openfiler · CWE-79 | Medium6.1 | — | 1.7% | Feb 7, 2020 |
24Monitor | CVE-2023-49488No exploit | A cross-site scripting (XSS) vulnerability in Openfiler ESA v2.99.1 allows attackers to execute arbitrary web scripts or HTML via injecting openfiler · openfiler · CWE-79 | Medium6.1 | — | 0.4% | Dec 11, 2023 |
17Monitor | CVE-2014-4309No exploit | Multiple cross-site scripting (XSS) vulnerabilities in Openfiler 2.99 allow remote attackers to inject arbitrary web script or HTML via the openfiler · openfiler · CWE-79 | Medium4.3 | — | 1.0% | Jun 18, 2014 |
- CVE-2014-719028Monitor
Multiple cross-site request forgery (CSRF) vulnerabilities in Openfiler 2.99.1 allow remote attackers to hijack the authentication of admini
MediumCVSS 6.8Proof of conceptEPSS 2%openfiler · openfilerSep 30, 2014
- CVE-2011-108624Monitor
Cross-site scripting (XSS) vulnerability in admin/system.html in Openfiler 2.3 allows remote attackers to inject arbitrary web script or HTM
MediumCVSS 6.1No exploitEPSS 2%openfiler · openfilerFeb 7, 2020
- CVE-2023-4948824Monitor
A cross-site scripting (XSS) vulnerability in Openfiler ESA v2.99.1 allows attackers to execute arbitrary web scripts or HTML via injecting
MediumCVSS 6.1No exploitEPSS 0%openfiler · openfilerDec 11, 2023
- CVE-2014-430917Monitor
Multiple cross-site scripting (XSS) vulnerabilities in Openfiler 2.99 allow remote attackers to inject arbitrary web script or HTML via the
MediumCVSS 4.3No exploitEPSS 1%openfiler · openfilerJun 18, 2014