VYPR

Slim

by Slims

CVEs (7)

  • CVE-2023-3744CriOct 2, 2023
    risk 0.64cvss 9.9epss 0.00

    Server-Side Request Forgery vulnerability in SLims version 9.6.0. This vulnerability could allow an authenticated attacker to send requests to internal services or upload the contents of relevant files via the "scrape_image.php" file in the imageURL parameter.

  • CVE-2013-4412HigNov 4, 2019
    risk 0.49cvss 7.5epss 0.03

    slim has NULL pointer dereference when using crypt() method from glibc 2.17

  • CVE-2025-26200HigFeb 24, 2025
    risk 0.47cvss 7.2epss 0.01

    SQL injection in SLIMS v.9.6.1 allows a remote attacker to escalate privileges via the month parameter in the visitor_report_day.php component.

  • CVE-2025-65233MedDec 17, 2025
    risk 0.40cvss 6.1epss 0.00

    Reflected cross-site scripting (XSS) in SLiMS (slims9_bulian) before 9.6.0 via improper handling of $_SERVER['PHP_SELF' ] in index.php/sysconfig.inc.php, which allows remote attackers to execute arbitrary JavaScript in a victim's browser by supplying a crafted URL path.

  • CVE-2023-24086MedFeb 13, 2023
    risk 0.40cvss 6.1epss 0.00

    SLIMS v9.5.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /customs/loan_by_class.php?reportView.

  • CVE-2010-2945Aug 30, 2010
    risk 0.00cvss epss 0.00

    The default configuration of SLiM before 1.3.2 places ./ (dot slash) at the beginning of the default_path option, which might allow local users to gain privileges via a Trojan horse program in the current working directory, related to slim.conf and cfg.cpp.

  • CVE-2009-1756May 22, 2009
    risk 0.00cvss epss 0.00

    SLiM Simple Login Manager 1.3.0 places the X authority magic cookie (mcookie) on the command line when invoking xauth from (1) app.cpp and (2) switchuser.cpp, which allows local users to access the X session by listing the process and its arguments.