Search Results (45 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2018-19411 1 Paessler 1 Prtg Network Monitor 2024-11-21 N/A
PRTG Network Monitor before 18.2.40.1683 allows an authenticated user with a read-only account to create another user with a read-write account (including administrator) via an HTTP request because /api/addusers doesn't check, or doesn't properly check, user rights.
CVE-2018-19204 1 Paessler 1 Prtg Network Monitor 2024-11-21 N/A
PRTG Network Monitor before 18.3.44.2054 allows a remote authenticated attacker (with read-write privileges) to execute arbitrary code and OS commands with system privileges. When creating an HTTP Advanced Sensor, the user's input in the POST parameter 'proxyport_' is mishandled. The attacker can craft an HTTP request and override the 'writeresult' command-line parameter for HttpAdvancedSensor.exe to store arbitrary data in an arbitrary place on the file system. For example, the attacker can create an executable file in the \Custom Sensors\EXE directory and execute it by creating EXE/Script Sensor.
CVE-2018-19203 1 Paessler 1 Prtg Network Monitor 2024-11-21 N/A
PRTG Network Monitor before 18.2.41.1652 allows remote unauthenticated attackers to terminate the PRTG Core Server Service via a special HTTP request.
CVE-2018-14683 1 Paessler 1 Prtg Network Monitor 2024-11-21 N/A
PRTG before 19.1.49.1966 has Cross Site Scripting (XSS) in the WEBGUI.
CVE-2018-10253 1 Paessler 1 Prtg Network Monitor 2024-11-21 N/A
Paessler PRTG Network Monitor before 18.1.39.1648 mishandles stack memory during unspecified API calls.