VYPR
Vendor

Klogserver

Products
1
CVEs
2
Across products
2
Status
Private

Products

1

Recent CVEs

2
  • CVE-2020-35729CriDec 27, 2020
    risk 0.74cvss 9.8epss 0.88

    KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.

  • CVE-2021-3317HigJan 26, 2021
    risk 0.64cvss 8.8epss 0.41

    KLog Server through 2.4.1 allows authenticated command injection. async.php calls shell_exec() on the original value of the source parameter.