Filtered by vendor Eve-ng
Subscribe
Total
2 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-31366 | 1 Eve-ng | 1 Eve-ng | 2022-10-21 | N/A | 7.2 HIGH |
An arbitrary file upload vulnerability in the apiImportLabs function in api_labs.php of EVE-NG 2.0.3-112 Community allows attackers to execute arbitrary code via a crafted UNL file. | |||||
CVE-2022-27903 | 1 Eve-ng | 1 Eve-ng | 2022-05-11 | 9.0 HIGH | 8.8 HIGH |
An OS Command Injection vulnerability in the configuration parser of Eve-NG Professional through 4.0.1-65 and Eve-NG Community through 2.0.3-112 allows a remote authenticated attacker to execute commands as root by editing virtualization command parameters of imported UNL files. |