Vendor
EDirectoryPro
Products
1
CVEs
4
Across products
4
Status
Private
Products
1- 4 CVEs
Recent CVEs
4| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-25675 | Hig | 0.53 | 8.2 | 0.01 | Apr 5, 2026 | eDirectory contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to bypass administrator authentication and disclose sensitive files by injecting SQL code into parameters. Attackers can exploit the key parameter in the login endpoint with… | ||
| CVE-2018-17950 | Hig | 0.49 | 7.5 | 0.01 | Dec 12, 2018 | Incorrect enforcement of authorization checks in eDirectory prior to 9.1 SP2 | ||
| CVE-2018-17952 | Med | 0.40 | 6.1 | 0.01 | Dec 12, 2018 | Cross site scripting vulnerability in eDirectory prior to 9.1 SP2 | ||
| CVE-2006-2296 | 0.03 | — | 0.01 | May 10, 2006 | SQL injection vulnerability in search_result.asp in EDirectoryPro 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the keyword parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. |
- risk 0.53cvss 8.2epss 0.01
eDirectory contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to bypass administrator authentication and disclose sensitive files by injecting SQL code into parameters. Attackers can exploit the key parameter in the login endpoint with…
- risk 0.49cvss 7.5epss 0.01
Incorrect enforcement of authorization checks in eDirectory prior to 9.1 SP2
- risk 0.40cvss 6.1epss 0.01
Cross site scripting vulnerability in eDirectory prior to 9.1 SP2
- CVE-2006-2296May 10, 2006risk 0.03cvss —epss 0.01
SQL injection vulnerability in search_result.asp in EDirectoryPro 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the keyword parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.