Sysax / Multi Server
12 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2023-54337 | Sysax Multi Server 6.95 - 'Password' Denial of Service (PoC) | MEDIUM | 5.1 | Jan 13, 2026 |
| CVE-2012-10060 | Sysax Multi Server < 5.55 SSH Username Buffer Overflow | CRITICAL | 9.3 | Aug 13, 2025 |
| CVE-2013-10065 | Sysax Multi-Server <= 6.10 SSHD Key Exchange DoS | HIGH | 8.7 | Aug 5, 2025 |
| CVE-2024-53458 | Sysax Multi Server 6.99 is vulnerable to a denial of service (DoS) condition when processing specially crafted SSH packets. | HIGH | 7.5 | Mar 5, 2025 |
| CVE-2024-53459 | Sysax Multi Server 6.99 is vulnerable to Cross Site Scripting (XSS) via the /scgi?sid parameter. | MEDIUM | 6.1 | Dec 2, 2024 |
| CVE-2020-23574 | When uploading a file in Sysax Multi Server 6.90, an authenticated user can modify the filename="" parameter in the uploadfile_name1.htm form to a length of 36… | MEDIUM | 6.5 | Aug 19, 2020 |
| CVE-2020-13227 | An issue was discovered in Sysax Multi Server 6.90. An attacker can determine the username (under which the web server is running) by triggering an invalid pat… | MEDIUM | 5.3 | Jun 2, 2020 |
| CVE-2020-13228 | An issue was discovered in Sysax Multi Server 6.90. There is reflected XSS via the /scgi sid parameter. | MEDIUM | 6.1 | Jun 2, 2020 |
| CVE-2020-13229 | An issue was discovered in Sysax Multi Server 6.90. A session can be hijacked if one observes the sid value in any /scgi URI, because it is an authentication t… | HIGH | 8.8 | Jun 2, 2020 |
| CVE-2012-6530 | Stack-based buffer overflow in Sysax Multi Server before 5.52, when HTTP is enabled, allows remote authenticated users with the create folder permission to exe… | HIGH | 7.1 | Jan 31, 2013 |
| CVE-2009-4800 | Directory traversal vulnerability in Sysax Multi Server 4.3 and 4.5 allows remote authenticated users to delete arbitrary files via a ..// (dot dot slash slash… | MEDIUM | 4.0 | Apr 22, 2010 |
| CVE-2009-4790 | Multiple directory traversal vulnerabilities in Sysax Multi Server 4.5 allow remote authenticated users to read or modify arbitrary files via crafted FTP comma… | HIGH | 9.0 | Apr 22, 2010 |
Showing 1 to 12 of 12 CVEs