VYPR

Monitoring Software

by Serverscheck

CVEs (2)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2017-17832Med0.355.40.00Dec 27, 2017ServersCheck Monitoring Software before 14.2.3 is prone to a cross-site scripting vulnerability as user supplied-data is not validated/sanitized when passed in the settings_SMS_ALERT_TYPE parameter, and JavaScript can be executed on settings-save.html (the Settings - SMS Alerts page).
CVE-2005-17980.000.00May 29, 2005Directory traversal vulnerability in ServersCheck Monitoring Software 5.9.0 to 5.10.0 allows remote attackers to read arbitrary files via .. (dot dot) sequences in an HTTP request.