Skip to content
Noroxi

quickbox records

5 published records for vendor quickbox.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

5 records
  • QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execute code on the server

    HighCVSS 8.8Proof of conceptEPSS 17%

    quickbox · quickboxJun 1, 2020

  • In QuickBox Pro v2.5.8 and below, the config.php file has a variable which takes a GET parameter value and parses it into a shell_exec('');

    HighCVSS 8.8No exploitEPSS 4%

    quickbox · quickboxJan 24, 2022

  • In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user can execute sudo mysql without a password

    HighCVSS 8.8No exploitEPSS 2%

    quickbox · quickboxJun 1, 2020

  • In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user has sudo privileges to execute grep as ro

    HighCVSS 7.2No exploitEPSS 2%

    quickbox · quickboxJun 1, 2020

  • QuickBox Pro v2.4.8 contains a cross-site scripting (XSS) vulnerability at "adminuseredit.php?usertoedit=XSS", as the user supplied input fo

    MediumCVSS 6.1No exploitEPSS 1%

    quickbox · quickboxFeb 7, 2022