Filtered by vendor Solarwinds Subscriptions
Total 266 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2017-5199 1 Solarwinds 1 Log And Event Manager 2024-08-05 N/A
The editbanner feature in SolarWinds LEM (aka SIEM) through 6.3.1 allows remote authenticated users to execute arbitrary code by editing /usr/local/contego/scripts/mgrconfig.pl.
CVE-2018-19999 1 Solarwinds 1 Serv-u Ftp Server 2024-08-05 N/A
The local management interface in SolarWinds Serv-U FTP Server 15.1.6.25 has incorrect access controls that permit local users to bypass authentication in the application and execute code in the context of the Windows SYSTEM account, leading to privilege escalation. To exploit this vulnerability, an attacker must have local access the the host running Serv-U, and a Serv-U administrator have an active management console session.
CVE-2018-19934 1 Solarwinds 1 Serv-u Ftp Server 2024-08-05 N/A
SolarWinds Serv-U FTP Server 15.1.6.25 has reflected cross-site scripting (XSS) in the Web management interface via URL path and HTTP POST parameter.
CVE-2018-19386 1 Solarwinds 1 Database Performance Analyzer 2024-08-05 N/A
SolarWinds Database Performance Analyzer 11.1.457 contains an instance of Reflected XSS in its idcStateError component, where the page parameter is reflected into the HREF of the 'Try Again' Button on the page, aka a /iwc/idcStateError.iwc?page= URI.
CVE-2018-16791 1 Solarwinds 1 Sftp\/scp Server 2024-08-05 N/A
In SolarWinds SFTP/SCP Server through 2018-09-10, the configuration file is world readable and writable, and stores user passwords in an insecure manner, allowing an attacker to determine passwords for potentially privileged accounts. This also grants the attacker an ability to backdoor the server.
CVE-2018-16792 1 Solarwinds 1 Sftp\/scp Server 2024-08-05 9.1 Critical
SolarWinds SFTP/SCP server through 2018-09-10 is vulnerable to XXE via a world readable and writable configuration file that allows an attacker to exfiltrate data.
CVE-2018-16243 1 Solarwinds 1 Database Performance Analyzer 2024-08-05 5.4 Medium
SolarWinds Database Performance Analyzer (DPA) 11.1.468 and 12.0.3074 have several persistent XSS vulnerabilities, related to logViewer.iwc, centralManage.cen, userAdministration.iwc, database.iwc, alertManagement.iwc, eventAnnotations.iwc, and central.cen.
CVE-2018-15906 1 Solarwinds 1 Serv-u Ftp Server 2024-08-05 N/A
SolarWinds Serv-U FTP Server 15.1.6 allows remote authenticated users to execute arbitrary code by leveraging the Import feature and modifying a CSV file.
CVE-2018-13442 1 Solarwinds 1 Network Performance Monitor 2024-08-05 N/A
SolarWinds Network Performance Monitor 12.3 allows SQL Injection via the /api/ActiveAlertsOnThisEntity/GetActiveAlerts TriggeringObjectEntityNames parameter.
CVE-2018-12897 1 Solarwinds 1 Dameware Mini Remote Control 2024-08-05 N/A
SolarWinds DameWare Mini Remote Control before 12.1 has a Buffer Overflow.
CVE-2018-10240 1 Solarwinds 1 Serv-u 2024-08-05 N/A
SolarWinds Serv-U MFT before 15.1.6 HFv1 assigns authenticated users a low-entropy session token that can be included in requests to the application as a URL parameter in lieu of a session cookie. This session token's value can be brute-forced by an attacker to obtain the corresponding session cookie and hijack the user's session.
CVE-2018-10241 1 Solarwinds 1 Serv-u 2024-08-05 N/A
A denial of service vulnerability in SolarWinds Serv-U before 15.1.6 HFv1 allows an authenticated user to crash the application (with a NULL pointer dereference) via a specially crafted URL beginning with the /Web%20Client/ substring.
CVE-2019-20002 1 Solarwinds 1 Webhelpdesk 2024-08-05 7.8 High
Formula Injection exists in the export feature in SolarWinds WebHelpDesk 12.7.1 via a value (provided by a low-privileged user in the Subject field of a help request form) that is mishandled in a TicketActions/view?tab=group TSV export by an admin user.
CVE-2019-19829 1 Solarwinds 1 Serv-u Ftp Server 2024-08-05 5.4 Medium
A cross-site scripting (XSS) vulnerability exists in SolarWinds Serv-U FTP Server 15.1.7 in the email parameter, a different vulnerability than CVE-2018-19934 and CVE-2019-13182.
CVE-2019-17127 1 Solarwinds 1 Orion Platform 2024-08-05 6.1 Medium
A Stored Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 in many application forms. An attacker can inject an Angular expression and escape the Angular sandbox to achieve stored XSS. This can lead to privilege escalation.
CVE-2019-17125 1 Solarwinds 1 Orion Platform 2024-08-05 6.1 Medium
A Reflected Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 in many forms. An attacker can inject an Angular expression and escape the Angular sandbox to achieve stored XSS.
CVE-2019-16959 1 Solarwinds 1 Webhelpdesk 2024-08-05 6.5 Medium
SolarWinds Web Help Desk 12.7.0 allows CSV Injection, also known as Formula Injection, via a file attached to a ticket.
CVE-2019-16957 1 Solarwinds 1 Webhelpdesk 2024-08-05 5.4 Medium
SolarWinds Web Help Desk 12.7.0 allows XSS via the First Name field of a User Account.
CVE-2019-16956 1 Solarwinds 1 Web Help Desk 2024-08-05 5.4 Medium
SolarWinds Web Help Desk 12.7.0 allows XSS via the Request Type parameter of a ticket.
CVE-2019-16961 1 Solarwinds 1 Web Help Desk 2024-08-05 5.4 Medium
SolarWinds Web Help Desk 12.7.0 allows XSS via a Schedule Name.