RSS   Podatności dla 'Uptime infrastructure monitor'   RSS

2018-08-27
 
CVE-2015-9263

CWE-434
 

 
An issue was discovered in post2file.php in Up.Time Monitoring Station 7.5.0 (build 16) and 7.4.0 (build 13). It allows an attacker to upload an arbitrary file, such as a .php file that can execute arbitrary OS commands.

 
2017-07-20
 
CVE-2017-11471

 

 
IDERA Uptime Monitor 7.8 has SQL injection in /gadgets/definitions/uptime.CapacityWhatIfGadget/getmetrics.php via the element parameter.

 
 
CVE-2017-11470

CWE-79
 

 
IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 122200.

 
 
CVE-2017-11469

 

 
get2post.php in IDERA Uptime Monitor 7.8 has directory traversal in the file_name parameter.

 
2016-06-09
 
CVE-2015-8268

 

 
The up.time agent in Idera Uptime Infrastructure Monitor 7.5 and 7.6 on Linux allows remote attackers to read arbitrary files via unspecified vectors.

 
2015-12-31
 
CVE-2015-2896

 

 
The up.time client in Idera Uptime Infrastructure Monitor through 7.6 allows remote attackers to obtain potentially sensitive version, OS, process, and event-log information via a command.

 
 
CVE-2015-2895

 

 
Buffer overflow in the up.time client in Idera Uptime Infrastructure Monitor 7.4 might allow remote attackers to execute arbitrary code via long command input.

 
 
CVE-2015-2894

 

 
Format string vulnerability in the up.time client in Idera Uptime Infrastructure Monitor 6.0 and 7.2 allows remote attackers to cause a denial of service (application crash) via format string specifiers.

 


Copyright 2020, cxsecurity.com

 

Back to Top