Monitorix
Fibranet · 4 CVEs
CVE-2021-3325
CRITICAL
Monitorix 3.13.0 allows remote attackers to bypass Basic Authentication in a default installation (i.e., an installatio…
Jan 27, 2021
CVE-2013-7071
MEDIUM
Cross-site scripting (XSS) vulnerability in the handle_request function in lib/HTTPServer.pm in Monitorix before 3.4.0…
Dec 31, 2019
CVE-2013-7070
CRITICAL
The handle_request function in lib/HTTPServer.pm in Monitorix before 3.3.1 allows remote attackers to execute arbitrary…
Dec 31, 2019
CVE-2018-7649
MEDIUM
Monitorix before 3.10.1 allows XSS via CGI variables.
Aug 2, 2018
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2021-3325 | Monitorix 3.13.0 allows remote attackers to bypass Basic Authentication in a default installation (i.e., an installation without a hosts_deny option). This iss… | CRITICAL | 2.23% | Jan 27, 2021 |
| CVE-2013-7071 | Cross-site scripting (XSS) vulnerability in the handle_request function in lib/HTTPServer.pm in Monitorix before 3.4.0 allows remote attackers to inject arbitr… | MEDIUM | 1.11% | Dec 31, 2019 |
| CVE-2013-7070 | The handle_request function in lib/HTTPServer.pm in Monitorix before 3.3.1 allows remote attackers to execute arbitrary commands via shell metacharacters in th… | CRITICAL | 4.09% | Dec 31, 2019 |
| CVE-2018-7649 | Monitorix before 3.10.1 allows XSS via CGI variables. | MEDIUM | 0.65% | Aug 2, 2018 |
Showing 1 to 4 of 4 CVEs