Vulnerability index

Browse CVEs

42 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Phpipam HIGH 8.8
CVE-2020-7988

An issue was discovered in tools/pass-change/result.php in phpIPAM 1.4. CSRF can be used to change the password of any user/admin, to escalate privil…

No fix yet
Fix from $1,950 2020-03-04
Phpipam CRITICAL 9.8
CVE-2019-16695

phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter.php table parameter when action=add is used.

Fix: after 1.4
Fix from $2,300 2019-09-22
Phpipam CRITICAL 9.8
CVE-2019-16696

phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit.php table parameter when action=add is used.

Fix: after 1.4
Fix from $2,300 2019-09-22
Phpipam CRITICAL 9.8
CVE-2019-16692EPSS 10%

phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is used.

Fix: after 1.4
Fix from $2,300 2019-09-22
Phpipam CRITICAL 9.8
CVE-2019-16693

phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/order.php table parameter when action=add is used.

Fix: after 1.4
Fix from $2,300 2019-09-22
Phpipam CRITICAL 9.8
CVE-2019-16694

phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit-result.php table parameter when action=add is used.

Fix: after 1.4
Fix from $2,300 2019-09-22
Phpipam MEDIUM 6.1
CVE-2019-1000010

phpIPAM version 1.3.2 and earlier contains a Cross Site Scripting (XSS) vulnerability in subnet-scan-telnet.php that can result in executing code in …

Fix: after 1.3.2
Fix from $1,600 2019-02-04
Phpipam CRITICAL 9.8
CVE-2018-1000869

phpIPAM version 1.3.2 contains a CWE-89 vulnerability in /app/admin/nat/item-add-submit.php that can result in SQL Injection.. This attack appear to …

Patch available
Fix from $2,300 2018-12-20
Phpipam MEDIUM 5.4
CVE-2018-1000870

PHPipam version 1.3.2 and earlier contains a CWE-79 vulnerability in /app/admin/users/print-user.php that can result in Execute code in the victims b…

Fix: after 1.3.2
Fix from $1,600 2018-12-20
Phpipam MEDIUM 6.1
CVE-2018-10329

app/tools/mac-lookup/index.php in phpIPAM 1.3.1 has Reflected XSS on /tools/mac-lookup/ via the mac parameter.

Mitigation only
Fix from $1,600 2018-04-24
Phpipam MEDIUM 5.4
CVE-2017-15640

app/sections/user-menu.php in phpIPAM before 1.3.1 has XSS via the ip parameter.

Fix: 1.3.1+
Fix from $1,600 2018-04-21
Phpipam MEDIUM 6.1
CVE-2017-6481

Multiple Cross-Site Scripting (XSS) issues were discovered in phpipam 1.2. The vulnerabilities exist due to insufficient filtration of user-supplied …

Fix: after 1.2
Fix from $1,600 2017-03-05