Записи voipmonitor
5 опубликованных записей вендора voipmonitor.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-287 Improper Authentication1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
5 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
54В плане | CVE-2022-24260Proof of concept | A SQL injection vulnerability in Voipmonitor GUI before v24.96 allows attackers to escalate privileges to the Administrator level.voipmonitor · voipmonitor · CWE-89 | Критическая9,8 | — | 50,0 % | 4 февр. 2022 г. |
50В плане | CVE-2021-30461Proof of concept | A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61.voipmonitor · voipmonitor · CWE-94 | Критическая9,8 | — | 36,6 % | 29 мая 2021 г. |
40В плане | CVE-2022-24259Эксплойта нет | An incorrect check in the component cdr.php of Voipmonitor GUI before v24.96 allows unauthenticated attackers to escalate privileges via a cvoipmonitor · voipmonitor · CWE-287 | Критическая9,8 | — | 2,0 % | 4 февр. 2022 г. |
39Наблюдать | CVE-2021-41408Эксплойта нет | VoIPmonitor WEB GUI up to version 24.61 is affected by SQL injection through the "api.php" file and "user" parameter.voipmonitor · voipmonitor · CWE-89 | Критическая9,8 | — | 1,1 % | 17 июн. 2022 г. |
36Наблюдать | CVE-2022-24262Эксплойта нет | The config restore function of Voipmonitor GUI before v24.96 does not properly check files sent as restore archives, allowing remote attackevoipmonitor · voipmonitor · CWE-434 | Высокая8,8 | — | 1,8 % | 4 февр. 2022 г. |
- CVE-2022-2426054В плане
A SQL injection vulnerability in Voipmonitor GUI before v24.96 allows attackers to escalate privileges to the Administrator level.
КритическаяCVSS 9,8Proof of conceptEPSS 50 %voipmonitor · voipmonitor4 февр. 2022 г.
- CVE-2021-3046150В плане
A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61.
КритическаяCVSS 9,8Proof of conceptEPSS 37 %voipmonitor · voipmonitor29 мая 2021 г.
- CVE-2022-2425940В плане
An incorrect check in the component cdr.php of Voipmonitor GUI before v24.96 allows unauthenticated attackers to escalate privileges via a c
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %voipmonitor · voipmonitor4 февр. 2022 г.
- CVE-2021-4140839Наблюдать
VoIPmonitor WEB GUI up to version 24.61 is affected by SQL injection through the "api.php" file and "user" parameter.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %voipmonitor · voipmonitor17 июн. 2022 г.
- CVE-2022-2426236Наблюдать
The config restore function of Voipmonitor GUI before v24.96 does not properly check files sent as restore archives, allowing remote attacke
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %voipmonitor · voipmonitor4 февр. 2022 г.