Filtered by vendor Solarwinds
Subscriptions
Filtered by product Serv-u
Subscriptions
Total
27 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2020-27994 | 1 Solarwinds | 1 Serv-u | 2021-02-18 | 6.5 Medium |
SolarWinds Serv-U before 15.2.2 allows Authenticated Directory Traversal. | ||||
CVE-2020-35481 | 1 Solarwinds | 1 Serv-u | 2021-02-05 | 9.8 Critical |
SolarWinds Serv-U before 15.2.2 allows Unauthenticated Macro Injection. | ||||
CVE-2020-35482 | 1 Solarwinds | 1 Serv-u | 2021-02-04 | 5.4 Medium |
SolarWinds Serv-U before 15.2.2 allows authenticated reflected XSS. | ||||
CVE-2020-15573 | 1 Solarwinds | 1 Serv-u | 2020-07-13 | 6.1 Medium |
SolarWinds Serv-U File Server before 15.2.1 has a "Cross-script vulnerability," aka Case Numbers 00041778 and 00306421. | ||||
CVE-2020-15575 | 1 Solarwinds | 1 Serv-u | 2020-07-13 | 6.1 Medium |
SolarWinds Serv-U File Server before 15.2.1 allows XSS as demonstrated by Tenable Scan, aka Case Number 00484194. | ||||
CVE-2018-10240 | 1 Solarwinds | 1 Serv-u | 2018-06-25 | N/A |
SolarWinds Serv-U MFT before 15.1.6 HFv1 assigns authenticated users a low-entropy session token that can be included in requests to the application as a URL parameter in lieu of a session cookie. This session token's value can be brute-forced by an attacker to obtain the corresponding session cookie and hijack the user's session. | ||||
CVE-2018-10241 | 1 Solarwinds | 1 Serv-u | 2018-06-20 | N/A |
A denial of service vulnerability in SolarWinds Serv-U before 15.1.6 HFv1 allows an authenticated user to crash the application (with a NULL pointer dereference) via a specially crafted URL beginning with the /Web%20Client/ substring. |