Логотип exploitDog
bind:CVE-2018-19515
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-19515

Количество 2

Количество 2

nvd логотип

CVE-2018-19515

почти 7 лет назад

In Webgalamb through 7.0, system/ajax.php functionality is supposed to be available only to the administrator. However, by using one of the bgsend, atment_sddd1xGz, or xls_bgimport query parameters, most of these methods become available to unauthenticated users.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-475v-6wxg-c2rx

больше 3 лет назад

In Webgalamb through 7.0, system/ajax.php functionality is supposed to be available only to the administrator. However, by using one of the bgsend, atment_sddd1xGz, or xls_bgimport query parameters, most of these methods become available to unauthenticated users.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2018-19515

In Webgalamb through 7.0, system/ajax.php functionality is supposed to be available only to the administrator. However, by using one of the bgsend, atment_sddd1xGz, or xls_bgimport query parameters, most of these methods become available to unauthenticated users.

CVSS3: 9.8
6%
Низкий
почти 7 лет назад
github логотип
GHSA-475v-6wxg-c2rx

In Webgalamb through 7.0, system/ajax.php functionality is supposed to be available only to the administrator. However, by using one of the bgsend, atment_sddd1xGz, or xls_bgimport query parameters, most of these methods become available to unauthenticated users.

CVSS3: 9.8
6%
Низкий
больше 3 лет назад

Уязвимостей на страницу