← Back

Queuemetrics

queuemetrics

Vendor: Loway • 6 CVEs

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Loway
1Queuemetrics
Sep 11, 2024
Sep 8, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Loway - CWE-204: Observable Response Discrepancy
1Loway
1Queuemetrics
Sep 11, 2024
Sep 8, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Loway - CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
1Loway
1Queuemetrics
Sep 11, 2024
Sep 8, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Loway - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
1Loway
1Queuemetrics
Nov 21, 2024
Sep 9, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A SQL injection vulnerability at a tpf URI in Loway QueueMetrics before 19.04.1 allows remote authenticated attackers to execute arbitrary SQL commands via the TASKS_LIST__pt.querystring parameter.
1Loway
1Queuemetrics
Nov 21, 2024
Aug 13, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A SQL injection vulnerability in the qm_adm/qm_export_stats_run.do endpoint of Loway QueueMetrics before 19.10.21 allows remote authenticated users to execute arbitrary SQL commands via the exportId parameter.
1Loway
1Queuemetrics
Nov 21, 2024
Aug 13, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A SQL injection vulnerability at a tpf URI in Loway QueueMetrics before 19.10.21 allows remote authenticated attackers to execute arbitrary SQL commands via the TPF_XPAR1 parameter.