Vendor
Prophecyinternational
Products
2
CVEs
4
Across products
4
Status
Private
Products
2- 2 CVEs
- 2 CVEs
Recent CVEs
4| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2011-5247 | Hig | 0.49 | 7.5 | 0.01 | Jan 8, 2020 | Snare for Linux before 1.7.0 has password disclosure because the rendered page contains the field RemotePassword. | ||
| CVE-2019-11364 | Hig | 0.47 | 7.2 | 0.02 | Aug 29, 2019 | An OS Command Injection vulnerability in Snare Central before 7.4.5 allows remote authenticated attackers to inject arbitrary OS commands via the ServerConf/DataManagement/DiskManager.php FORMNAS_share parameter. | ||
| CVE-2019-11363 | Hig | 0.47 | 7.2 | 0.01 | Aug 29, 2019 | A SQL injection vulnerability in Snare Central before 7.4.5 allows remote authenticated attackers to execute arbitrary SQL commands via the AgentConsole/UserGroupQuery.php ShowUser parameter. | ||
| CVE-2011-5250 | Med | 0.42 | 6.5 | 0.01 | Jan 8, 2020 | Snare for Linux before 1.7.0 has CSRF in the web interface. |
- risk 0.49cvss 7.5epss 0.01
Snare for Linux before 1.7.0 has password disclosure because the rendered page contains the field RemotePassword.
- risk 0.47cvss 7.2epss 0.02
An OS Command Injection vulnerability in Snare Central before 7.4.5 allows remote authenticated attackers to inject arbitrary OS commands via the ServerConf/DataManagement/DiskManager.php FORMNAS_share parameter.
- risk 0.47cvss 7.2epss 0.01
A SQL injection vulnerability in Snare Central before 7.4.5 allows remote authenticated attackers to execute arbitrary SQL commands via the AgentConsole/UserGroupQuery.php ShowUser parameter.
- risk 0.42cvss 6.5epss 0.01
Snare for Linux before 1.7.0 has CSRF in the web interface.