RSS   Vulnerabilities for 'Network monitor'   RSS

2020-03-17
 
CVE-2019-11074

CWE-434
 

 
A Write to Arbitrary Location in Disk vulnerability exists in PRTG Network Monitor 19.1.49 and below that allows attackers to place files in arbitrary locations with SYSTEM privileges (although not controlling the contents of such files) due to insufficient sanitisation when passing arguments to the phantomjs.exe binary. In order to exploit the vulnerability, remote authenticated administrators need to create a new HTTP Full Web Page Sensor and set specific settings when executing the sensor.

 
2018-11-12
 
CVE-2018-19204

CWE-20
 

 
PRTG Network Monitor before 18.3.44.2054 allows a remote authenticated attacker (with read-write privileges) to execute arbitrary code and OS commands with system privileges. When creating an HTTP Advanced Sensor, the user's input in the POST parameter 'proxyport_' is mishandled. The attacker can craft an HTTP request and override the 'writeresult' command-line parameter for HttpAdvancedSensor.exe to store arbitrary data in an arbitrary place on the file system. For example, the attacker can create an executable file in the \Custom Sensors\EXE directory and execute it by creating EXE/Script Sensor.

 
 
CVE-2018-19203

CWE-20
 

 
PRTG Network Monitor before 18.2.41.1652 allows remote unauthenticated attackers to terminate the PRTG Core Server Service via a special HTTP request.

 

 >>> Vendor: Paessler 6 Products
Network monitor
Ipcheck server monitor
Prtg traffic grapher
Prtg traffic grapher6.0.5.416
Prtg network monitor
PRTG


Copyright 2024, cxsecurity.com

 

Back to Top