VYPR
Vendor

Cim Project

Products
1
CVEs
2
Across products
2
Status
Private

Products

1

Recent CVEs

2
  • CVE-2019-7692CriFeb 10, 2019
    risk 0.64cvss 9.8epss 0.02

    install/install.php in CIM 0.9.3 allows remote attackers to execute arbitrary PHP code via a crafted prefix value because of configuration file mishandling in the N=83 case, as demonstrated by a call to the PHP fputs function that creates a .php file in the public folder.

  • CVE-2018-20614HigDec 30, 2018
    risk 0.49cvss 7.5epss 0.01

    public\install\install.php in CIM 0.9.3 allows remote attackers to reload the product via the public/install/#/step3 URI.