Slim
by Slims
CVEs (7)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-3744 | Cri | 0.64 | 9.9 | 0.00 | Oct 2, 2023 | Server-Side Request Forgery vulnerability in SLims version 9.6.0. This vulnerability could allow an authenticated attacker to send requests to internal services or upload the contents of relevant files via the "scrape_image.php" file in the imageURL parameter. | ||
| CVE-2013-4412 | Hig | 0.49 | 7.5 | 0.03 | Nov 4, 2019 | slim has NULL pointer dereference when using crypt() method from glibc 2.17 | ||
| CVE-2025-26200 | Hig | 0.47 | 7.2 | 0.01 | Feb 24, 2025 | SQL injection in SLIMS v.9.6.1 allows a remote attacker to escalate privileges via the month parameter in the visitor_report_day.php component. | ||
| CVE-2025-65233 | Med | 0.40 | 6.1 | 0.00 | Dec 17, 2025 | Reflected cross-site scripting (XSS) in SLiMS (slims9_bulian) before 9.6.0 via improper handling of $_SERVER['PHP_SELF' ] in index.php/sysconfig.inc.php, which allows remote attackers to execute arbitrary JavaScript in a victim's browser by supplying a crafted URL path. | ||
| CVE-2023-24086 | Med | 0.40 | 6.1 | 0.00 | Feb 13, 2023 | SLIMS v9.5.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /customs/loan_by_class.php?reportView. | ||
| CVE-2010-2945 | 0.00 | — | 0.00 | Aug 30, 2010 | The default configuration of SLiM before 1.3.2 places ./ (dot slash) at the beginning of the default_path option, which might allow local users to gain privileges via a Trojan horse program in the current working directory, related to slim.conf and cfg.cpp. | |||
| CVE-2009-1756 | 0.00 | — | 0.00 | May 22, 2009 | SLiM Simple Login Manager 1.3.0 places the X authority magic cookie (mcookie) on the command line when invoking xauth from (1) app.cpp and (2) switchuser.cpp, which allows local users to access the X session by listing the process and its arguments. |
- risk 0.64cvss 9.9epss 0.00
Server-Side Request Forgery vulnerability in SLims version 9.6.0. This vulnerability could allow an authenticated attacker to send requests to internal services or upload the contents of relevant files via the "scrape_image.php" file in the imageURL parameter.
- risk 0.49cvss 7.5epss 0.03
slim has NULL pointer dereference when using crypt() method from glibc 2.17
- risk 0.47cvss 7.2epss 0.01
SQL injection in SLIMS v.9.6.1 allows a remote attacker to escalate privileges via the month parameter in the visitor_report_day.php component.
- risk 0.40cvss 6.1epss 0.00
Reflected cross-site scripting (XSS) in SLiMS (slims9_bulian) before 9.6.0 via improper handling of $_SERVER['PHP_SELF' ] in index.php/sysconfig.inc.php, which allows remote attackers to execute arbitrary JavaScript in a victim's browser by supplying a crafted URL path.
- risk 0.40cvss 6.1epss 0.00
SLIMS v9.5.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /customs/loan_by_class.php?reportView.
- CVE-2010-2945Aug 30, 2010risk 0.00cvss —epss 0.00
The default configuration of SLiM before 1.3.2 places ./ (dot slash) at the beginning of the default_path option, which might allow local users to gain privileges via a Trojan horse program in the current working directory, related to slim.conf and cfg.cpp.
- CVE-2009-1756May 22, 2009risk 0.00cvss —epss 0.00
SLiM Simple Login Manager 1.3.0 places the X authority magic cookie (mcookie) on the command line when invoking xauth from (1) app.cpp and (2) switchuser.cpp, which allows local users to access the X session by listing the process and its arguments.