← Back

Fibranet

fibranet

4 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Monitorix
monitorix

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Fedoraproject
Fibranet
2Fedora
Monitorix
Jun 17, 2026
Jan 27, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Monitorix 3.13.0 allows remote attackers to bypass Basic Authentication in a default installation (i.e., an installation without a hosts_deny option). This issue occurred because a new access-control feature was introduc...Show more
Monitorix 3.13.0 allows remote attackers to bypass Basic Authentication in a default installation (i.e., an installation without a hosts_deny option). This issue occurred because a new access-control feature was introduced without considering that some exiting installations became unsafe, upon an update to 3.13.0, unless the new feature was immediately configured.Show less
1Fibranet
1Monitorix
Nov 21, 2024
Dec 31, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the handle_request function in lib/HTTPServer.pm in Monitorix before 3.4.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
1Fibranet
1Monitorix
Nov 21, 2024
Dec 31, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The handle_request function in lib/HTTPServer.pm in Monitorix before 3.3.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the URI.
1Fibranet
1Monitorix
Jun 17, 2026
Aug 2, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Monitorix before 3.10.1 allows XSS via CGI variables.