quickbox records
5 published records for vendor quickbox.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')3
- CWE-269 Improper Privilege Management1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-13448Proof of concept | QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execute code on the serverquickbox · quickbox · CWE-78 | High8.8 | — | 17.4% | Jun 1, 2020 |
36Monitor | CVE-2021-44981No exploit | In QuickBox Pro v2.5.8 and below, the config.php file has a variable which takes a GET parameter value and parses it into a shell_exec(''); quickbox · quickbox · CWE-78 | High8.8 | — | 3.7% | Jan 24, 2022 |
36Monitor | CVE-2020-13694No exploit | In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user can execute sudo mysql without a passwordquickbox · quickbox · CWE-78 | High8.8 | — | 2.0% | Jun 1, 2020 |
29Monitor | CVE-2020-13695No exploit | In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user has sudo privileges to execute grep as roquickbox · quickbox · CWE-269 | High7.2 | — | 1.7% | Jun 1, 2020 |
24Monitor | CVE-2021-45281No exploit | QuickBox Pro v2.4.8 contains a cross-site scripting (XSS) vulnerability at "adminuseredit.php?usertoedit=XSS", as the user supplied input foquickbox · quickbox · CWE-79 | Medium6.1 | — | 0.7% | Feb 7, 2022 |
- CVE-2020-1344840Plan
QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execute code on the server
HighCVSS 8.8Proof of conceptEPSS 17%quickbox · quickboxJun 1, 2020
- CVE-2021-4498136Monitor
In QuickBox Pro v2.5.8 and below, the config.php file has a variable which takes a GET parameter value and parses it into a shell_exec('');
HighCVSS 8.8No exploitEPSS 4%quickbox · quickboxJan 24, 2022
- CVE-2020-1369436Monitor
In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user can execute sudo mysql without a password
HighCVSS 8.8No exploitEPSS 2%quickbox · quickboxJun 1, 2020
- CVE-2020-1369529Monitor
In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user has sudo privileges to execute grep as ro
HighCVSS 7.2No exploitEPSS 2%quickbox · quickboxJun 1, 2020
- CVE-2021-4528124Monitor
QuickBox Pro v2.4.8 contains a cross-site scripting (XSS) vulnerability at "adminuseredit.php?usertoedit=XSS", as the user supplied input fo
MediumCVSS 6.1No exploitEPSS 1%quickbox · quickboxFeb 7, 2022