VYPR

Uptime Infrastructure Monitor

Sign in to watch

by Idera

CVEs (6)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2017-11471Cri0.679.80.01Jul 20, 2017IDERA Uptime Monitor 7.8 has SQL injection in /gadgets/definitions/uptime.CapacityWhatIfGadget/getmetrics.php via the element parameter.
CVE-2017-11470Cri0.679.80.01Jul 20, 2017IDERA Uptime Monitor 7.8 has SQL injection in /gadgets/definitions/uptime.CapacityWhatifGadget/getxenmetrics.php via the element parameter.
CVE-2017-11469Hig0.527.50.07Jul 20, 2017get2post.php in IDERA Uptime Monitor 7.8 has directory traversal in the file_name parameter.
CVE-2015-2895Hig0.487.30.04Dec 31, 2015Buffer overflow in the up.time client in Idera Uptime Infrastructure Monitor 7.4 might allow remote attackers to execute arbitrary code via long command input.
CVE-2015-2894Med0.355.30.01Dec 31, 2015Format string vulnerability in the up.time client in Idera Uptime Infrastructure Monitor 6.0 and 7.2 allows remote attackers to cause a denial of service (application crash) via format string specifiers.
CVE-2015-2896Med0.345.30.00Dec 31, 2015The up.time client in Idera Uptime Infrastructure Monitor through 7.6 allows remote attackers to obtain potentially sensitive version, OS, process, and event-log information via a command.