Skip to main content

Vendor archive

combodo CVEs

Beta · best-effort

82 CVEs tagged to vendor combodo4 Critical, 40 High, 37 Medium, 1 Low, 0 Unrated.

CVE-2019-13965

Published Feb 14, 2020

Because of a lack of sanitization around error messages, multiple Reflective XSS issues exist in iTop through 2.6.0 via the param_file parameter to webservices/export.php, webserv…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11215

Published Feb 14, 2020

In Combodo iTop 2.2.0 through 2.6.0, if the configuration file is writable, then execution of arbitrary code can be accomplished by calling ajax.dataloader with a maliciously craf…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-10863

Published Apr 4, 2019

A command injection vulnerability exists in TeemIp versions before 2.4.0. The new_config parameter of exec.php allows one to create a new PHP file with the exception of config inf…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2018-10642

Published May 2, 2018

Command injection vulnerability in Combodo iTop 2.4.1 allows remote authenticated administrators to execute arbitrary commands by changing the platform configuration, because web/…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2015-6544

Published Feb 20, 2018

Cross-site scripting (XSS) vulnerability in application/dashboard.class.inc.php in Combodo iTop before 2.2.0-2459 allows remote attackers to inject arbitrary web script or HTML vi…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0805

Published Mar 20, 2014

Multiple cross-site scripting (XSS) vulnerabilities in the search feature in iTop (aka IT Operations Portal) 2.0, 1.2.1, 1.2, and earlier allow remote attackers to inject arbitrar…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4275

Published Nov 26, 2011

Multiple cross-site scripting (XSS) vulnerabilities in iTop (aka IT Operations Portal) 1.1.181 and 1.2.0-RC-282 allow remote attackers to inject arbitrary web script or HTML via (…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 76-82 of 82 CVEsPage 4 of 4