Vulnerabilities
5 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-36306 | A Cross Site Scripting (XSS) vulnerability in Adiscon Aiscon LogAnalyzer through 4.1.13 allows a remote attacker to execute arbitrary code via the asktheoracle. A Cross Site Scripting (XSS) vulnerability in Adiscon Aiscon LogAnalyzer through 4.1.13 allows a remote attacker to execute arbitrary code via the asktheoracle.php, details.php, index.php, search.php, export.php, reports.php, and statistics.php components. NVD description · AI analysis pending | 6.1 | 5% | PoC |
| — | |
| CVE-2023-34600 | Adiscon LogAnalyzer v4.1.13 and before is vulnerable to SQL Injection. Adiscon LogAnalyzer v4.1.13 and before is vulnerable to SQL Injection. NVD description · AI analysis pending | 9.8 | 24% | PoC |
| — | |
| CVE-2022-36664 | Password Manager for IIS 2.0 has a cross-site scripting (XSS) vulnerability via the /isapi/PasswordManager.dll ResultURL parameter. Password Manager for IIS 2.0 has a cross-site scripting (XSS) vulnerability via the /isapi/PasswordManager.dll ResultURL parameter. NVD description · AI analysis pending | 6.1 | 4% | PoC |
| — | |
| CVE-2021-31738 | Adiscon LogAnalyzer 4.1.10 and 4.1.11 allow login.php XSS. Adiscon LogAnalyzer 4.1.10 and 4.1.11 allow login.php XSS. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2018-19877 | login.php in Adiscon LogAnalyzer before 4.1.7 has XSS via the Login Button Referer field. login.php in Adiscon LogAnalyzer before 4.1.7 has XSS via the Login Button Referer field. NVD description · AI analysis pending | 6.1 | 19% | PoC |
| — |