voipmonitor kayıtları
voipmonitor üreticisine ait 5 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-287 Improper Authentication1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
5 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
54Planlayın | CVE-2022-24260Kavram kanıtı | A SQL injection vulnerability in Voipmonitor GUI before v24.96 allows attackers to escalate privileges to the Administrator level.voipmonitor · voipmonitor · CWE-89 | Kritik9,8 | — | %50,0 | 4 Şub 2022 |
50Planlayın | CVE-2021-30461Kavram kanıtı | A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61.voipmonitor · voipmonitor · CWE-94 | Kritik9,8 | — | %36,6 | 29 May 2021 |
40Planlayın | CVE-2022-24259İstismar yok | An incorrect check in the component cdr.php of Voipmonitor GUI before v24.96 allows unauthenticated attackers to escalate privileges via a cvoipmonitor · voipmonitor · CWE-287 | Kritik9,8 | — | %2,0 | 4 Şub 2022 |
39İzleyin | CVE-2021-41408İstismar yok | VoIPmonitor WEB GUI up to version 24.61 is affected by SQL injection through the "api.php" file and "user" parameter.voipmonitor · voipmonitor · CWE-89 | Kritik9,8 | — | %1,1 | 17 Haz 2022 |
36İzleyin | CVE-2022-24262İstismar yok | The config restore function of Voipmonitor GUI before v24.96 does not properly check files sent as restore archives, allowing remote attackevoipmonitor · voipmonitor · CWE-434 | Yüksek8,8 | — | %1,8 | 4 Şub 2022 |
- CVE-2022-2426054Planlayın
A SQL injection vulnerability in Voipmonitor GUI before v24.96 allows attackers to escalate privileges to the Administrator level.
KritikCVSS 9,8Kavram kanıtıEPSS %50voipmonitor · voipmonitor4 Şub 2022
- CVE-2021-3046150Planlayın
A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61.
KritikCVSS 9,8Kavram kanıtıEPSS %37voipmonitor · voipmonitor29 May 2021
- CVE-2022-2425940Planlayın
An incorrect check in the component cdr.php of Voipmonitor GUI before v24.96 allows unauthenticated attackers to escalate privileges via a c
KritikCVSS 9,8İstismar yokEPSS %2voipmonitor · voipmonitor4 Şub 2022
- CVE-2021-4140839İzleyin
VoIPmonitor WEB GUI up to version 24.61 is affected by SQL injection through the "api.php" file and "user" parameter.
KritikCVSS 9,8İstismar yokEPSS %1voipmonitor · voipmonitor17 Haz 2022
- CVE-2022-2426236İzleyin
The config restore function of Voipmonitor GUI before v24.96 does not properly check files sent as restore archives, allowing remote attacke
YüksekCVSS 8,8İstismar yokEPSS %2voipmonitor · voipmonitor4 Şub 2022