Monitorix
by Fibranet
Source repositories
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2013-7070 | Cri | 0.57 | 9.8 | 0.04 | Dec 31, 2019 | The handle_request function in lib/HTTPServer.pm in Monitorix before 3.3.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the URI. | ||
| CVE-2018-7649 | Med | 0.40 | 6.1 | 0.01 | Aug 2, 2018 | Monitorix before 3.10.1 allows XSS via CGI variables. | ||
| CVE-2013-7071 | Med | 0.33 | 6.1 | 0.01 | Dec 31, 2019 | Cross-site scripting (XSS) vulnerability in the handle_request function in lib/HTTPServer.pm in Monitorix before 3.4.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. | ||
| CVE-2021-3325 | Cri | 0.00 | 9.8 | 0.02 | Jan 27, 2021 | Monitorix 3.13.0 allows remote attackers to bypass Basic Authentication in a default installation (i.e., an installation without a hosts_deny option). This issue occurred because a new access-control feature was introduced without considering that some exiting installations… |
- risk 0.57cvss 9.8epss 0.04
The handle_request function in lib/HTTPServer.pm in Monitorix before 3.3.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the URI.
- risk 0.40cvss 6.1epss 0.01
Monitorix before 3.10.1 allows XSS via CGI variables.
- risk 0.33cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in the handle_request function in lib/HTTPServer.pm in Monitorix before 3.4.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
- risk 0.00cvss 9.8epss 0.02
Monitorix 3.13.0 allows remote attackers to bypass Basic Authentication in a default installation (i.e., an installation without a hosts_deny option). This issue occurred because a new access-control feature was introduced without considering that some exiting installations…