Loganalyzer
by Adiscon
CVEs (6)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-34600 | Cri | 0.66 | 9.8 | 0.24 | Jun 20, 2023 | Adiscon LogAnalyzer v4.1.13 and before is vulnerable to SQL Injection. | ||
| CVE-2018-19877 | Med | 0.44 | 6.1 | 0.19 | Dec 5, 2018 | login.php in Adiscon LogAnalyzer before 4.1.7 has XSS via the Login Button Referer field. | ||
| CVE-2023-36306 | Med | 0.43 | 6.1 | 0.04 | Aug 8, 2023 | A Cross Site Scripting (XSS) vulnerability in Adiscon Aiscon LogAnalyzer through 4.1.13 allows a remote attacker to execute arbitrary code via the asktheoracle.php, details.php, index.php, search.php, export.php, reports.php, and statistics.php components. | ||
| CVE-2021-31738 | Med | 0.40 | 6.1 | 0.01 | Jun 8, 2021 | Adiscon LogAnalyzer 4.1.10 and 4.1.11 allow login.php XSS. | ||
| CVE-2014-6070 | 0.03 | — | 0.04 | Sep 11, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Adiscon LogAnalyzer before 3.6.6 allow remote attackers to inject arbitrary web script or HTML via the hostname in (1) index.php or (2) detail.php. | |||
| CVE-2012-3790 | 0.00 | — | 0.01 | Jun 20, 2012 | Cross-site scripting (XSS) vulnerability in index.php in Adiscon LogAnalyzer before 3.4.4 and 3.5.x before 3.5.5 allows remote attackers to inject arbitrary web script or HTML via the highlight parameter in a Search action. |
- risk 0.66cvss 9.8epss 0.24
Adiscon LogAnalyzer v4.1.13 and before is vulnerable to SQL Injection.
- risk 0.44cvss 6.1epss 0.19
login.php in Adiscon LogAnalyzer before 4.1.7 has XSS via the Login Button Referer field.
- risk 0.43cvss 6.1epss 0.04
A Cross Site Scripting (XSS) vulnerability in Adiscon Aiscon LogAnalyzer through 4.1.13 allows a remote attacker to execute arbitrary code via the asktheoracle.php, details.php, index.php, search.php, export.php, reports.php, and statistics.php components.
- risk 0.40cvss 6.1epss 0.01
Adiscon LogAnalyzer 4.1.10 and 4.1.11 allow login.php XSS.
- CVE-2014-6070Sep 11, 2014risk 0.03cvss —epss 0.04
Multiple cross-site scripting (XSS) vulnerabilities in Adiscon LogAnalyzer before 3.6.6 allow remote attackers to inject arbitrary web script or HTML via the hostname in (1) index.php or (2) detail.php.
- CVE-2012-3790Jun 20, 2012risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in index.php in Adiscon LogAnalyzer before 3.4.4 and 3.5.x before 3.5.5 allows remote attackers to inject arbitrary web script or HTML via the highlight parameter in a Search action.