Search Results (Refine Search)
- Results Type: Overview
- Keyword (text search): cpe:2.3:a:lansweeper:lansweeper:4.0.0.106:*:*:*:*:*:*:*
- CPE Name Search: true
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2019-13462 |
Lansweeper before 7.1.117.4 allows unauthenticated SQL injection. Published: August 12, 2019; 1:15:11 PM -0400 |
V3.0: 9.1 CRITICAL V2.0: 6.4 MEDIUM |
CVE-2015-9264 |
Lansweeper 4.x through 6.x before 6.0.0.48 allows attackers to execute arbitrary code on the administrator's workstation via a crafted Windows service. Published: August 27, 2018; 12:29:00 AM -0400 |
V3.0: 9.8 CRITICAL V2.0: 7.5 HIGH |
CVE-2017-16841 |
LanSweeper 6.0.100.75 has XSS via the description parameter to /Calendar/CalendarActions.aspx. Published: November 15, 2017; 10:29:00 PM -0500 |
V3.0: 6.1 MEDIUM V2.0: 4.3 MEDIUM |
CVE-2017-13706 |
XML external entity (XXE) vulnerability in the import package functionality of the deployment module in Lansweeper before 6.0.100.67 allows remote authenticated users to obtain sensitive information, cause a denial of service, conduct server-side request forgery (SSRF) attacks, conduct internal port scans, or have unspecified other impact via an XML request, aka bug #572705. Published: October 10, 2017; 9:29:00 AM -0400 |
V3.0: 9.9 CRITICAL V2.0: 6.5 MEDIUM |
CVE-2017-9292 |
Lansweeper before 6.0.0.65 has XSS in an image retrieval URI, aka Bug 542782. Published: May 29, 2017; 1:29:00 PM -0400 |
V3.0: 6.1 MEDIUM V2.0: 4.3 MEDIUM |