VYPR
Vendor

Hashtopus Project

Products
1
CVEs
3
Across products
3
Status
Private

Products

1

Recent CVEs

3
  • CVE-2017-11679HigJul 27, 2017
    risk 0.57cvss 8.8epss 0.00

    Cross-Site Request Forgery (CSRF) exists in Hashtopus 1.5g via the password parameter to admin.php in an a=config action.

  • CVE-2017-11678HigJul 27, 2017
    risk 0.57cvss 8.8epss 0.01

    SQL injection vulnerability in Hashtopus 1.5g allows remote authenticated users to execute arbitrary SQL commands via the format parameter in admin.php.

  • CVE-2017-11677MedJul 27, 2017
    risk 0.40cvss 6.1epss 0.00

    Cross-site scripting (XSS) vulnerability in Hashtopus 1.5g allows remote attackers to inject arbitrary web script or HTML via the query string to admin.php.