Vulnerabilities
Vulnerable Software
Solarwinds:  Security Vulnerabilities
A cross-site scripting (XSS) vulnerability exists in SolarWinds Serv-U FTP Server 15.1.7 in the email parameter, a different vulnerability than CVE-2018-19934 and CVE-2019-13182.
CVSS Score
5.4
EPSS Score
0.023
Published
2019-12-18
A CSV injection vulnerability exists in the web UI of SolarWinds Serv-U FTP Server v15.1.7.
CVSS Score
6.5
EPSS Score
0.032
Published
2019-12-16
A stored cross-site scripting (XSS) vulnerability exists in the web UI of SolarWinds Serv-U FTP Server 15.1.7.
CVSS Score
5.4
EPSS Score
0.064
Published
2019-12-16
The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to upload an executable to be executed on the DWRCS.exe host. An unauthenticated, remote attacker can request smart card login and upload and execute an arbitrary executable run under the Local System account.
CVSS Score
9.8
EPSS Score
0.051
Published
2019-10-08
SolarWinds Database Performance Analyzer 11.1.457 contains an instance of Reflected XSS in its idcStateError component, where the page parameter is reflected into the HREF of the 'Try Again' Button on the page, aka a /iwc/idcStateError.iwc?page= URI.
CVSS Score
6.1
EPSS Score
0.09
Published
2019-08-14
SolarWinds Network Performance Monitor 12.3 allows SQL Injection via the /api/ActiveAlertsOnThisEntity/GetActiveAlerts TriggeringObjectEntityNames parameter.
CVSS Score
8.8
EPSS Score
0.017
Published
2019-07-16
A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.
CVSS Score
8.8
EPSS Score
0.66
Published
2019-06-17
Dameware Remote Mini Control version 12.1.0.34 and prior contains an unauthenticated remote buffer over-read due to the server not properly validating RsaSignatureLen during key negotiation, which could crash the application or leak sensitive information.
CVSS Score
7.4
EPSS Score
0.256
Published
2019-06-07
The local management interface in SolarWinds Serv-U FTP Server 15.1.6.25 has incorrect access controls that permit local users to bypass authentication in the application and execute code in the context of the Windows SYSTEM account, leading to privilege escalation. To exploit this vulnerability, an attacker must have local access the the host running Serv-U, and a Serv-U administrator have an active management console session.
CVSS Score
7.8
EPSS Score
0.006
Published
2019-06-07
DWRCC in SolarWinds DameWare Mini Remote Control 10.0 x64 has a Buffer Overflow associated with the size field for the machine name.
CVSS Score
7.5
EPSS Score
0.206
Published
2019-05-02


Contact Us

Shodan ® - All rights reserved