Vulnerabilities
Vulnerable Software
Status:  Security Vulnerabilities
It is identified a vulnerability of insufficient authentication in an important specific function of Status PowerBPM. A LAN attacker with normal user privilege can exploit this vulnerability to modify substitute agent to arbitrary users, resulting in serious consequence.
CVSS Score
5.7
EPSS Score
0.003
Published
2023-06-02
statusnet through 2010 allows attackers to spoof syslog messages via newline injection attacks.
CVSS Score
5.3
EPSS Score
0.009
Published
2020-02-07
Cross-site scripting (XSS) vulnerability in statusnet through 2010 in error message contents.
CVSS Score
6.1
EPSS Score
0.009
Published
2019-11-20
Unspecified vulnerability in statusnet through 2010 due to the way addslashes are used in SQL string escapes..
CVSS Score
9.8
EPSS Score
0.013
Published
2019-11-20
statusnet before 0.9.9 has XSS
CVSS Score
6.1
EPSS Score
0.01
Published
2019-11-12
ubuntu-server.js in Status React Native Desktop before v0.57.8_mobile_ui allows Remote Code Execution.
CVSS Score
9.8
EPSS Score
0.041
Published
2019-07-23
Multiple SQL injection vulnerabilities in StatusNet 1.0 before 1.0.2 and 1.1.0 allow remote attackers to execute arbitrary SQL commands via vectors related to user lists and "a particular tag format."
CVSS Score
7.5
EPSS Score
0.011
Published
2013-10-11
StatusNet 0.9.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by tpl/index.php and certain other files.
CVSS Score
5.0
EPSS Score
0.012
Published
2011-09-24


Contact Us

Shodan ® - All rights reserved