← Back

Serverscheck

serverscheck

5 CVEs • 2 products

Products (2)

Click to collapse
Toggle

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Serverscheck
1Monitoring Software
Nov 21, 2024
Oct 24, 2018
N/A· v4
6.5 MEDIUM· v3
5.0 MEDIUM· v2
ServersCheck Monitoring Software through 14.3.3 allows local users to cause a denial of service (menu functionality loss) by creating an LNK file that points to a second LNK file, if this second LNK file is associated wi...Show more
ServersCheck Monitoring Software through 14.3.3 allows local users to cause a denial of service (menu functionality loss) by creating an LNK file that points to a second LNK file, if this second LNK file is associated with a Start menu. Ultimately, this behavior comes from a Directory Traversal bug (via the sensor_details.html id parameter) that allows creating empty files in arbitrary directories.Show less
1Serverscheck
1Monitoring Software
Nov 21, 2024
Oct 24, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
ServersCheck Monitoring Software through 14.3.3 has Persistent and Reflected XSS via the sensors.html status parameter, sensors.html type parameter, sensors.html device parameter, report.html location parameter, group_de...Show more
ServersCheck Monitoring Software through 14.3.3 has Persistent and Reflected XSS via the sensors.html status parameter, sensors.html type parameter, sensors.html device parameter, report.html location parameter, group_delete.html group parameter, report_save.html query parameter, sensors.html location parameter, or group_delete.html group parameter.Show less
1Serverscheck
1Serverscheck
Nov 21, 2024
Oct 21, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
ServersCheck Monitoring Software before 14.3.4 allows SQL Injection by an authenticated user.
1Serverscheck
1Monitoring Software
May 13, 2026
Dec 27, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
ServersCheck Monitoring Software before 14.2.3 is prone to a cross-site scripting vulnerability as user supplied-data is not validated/sanitized when passed in the settings_SMS_ALERT_TYPE parameter, and JavaScript can be...Show more
ServersCheck Monitoring Software before 14.2.3 is prone to a cross-site scripting vulnerability as user supplied-data is not validated/sanitized when passed in the settings_SMS_ALERT_TYPE parameter, and JavaScript can be executed on settings-save.html (the Settings - SMS Alerts page).Show less
1Serverscheck
1Monitoring Software
Apr 16, 2026
May 29, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in ServersCheck Monitoring Software 5.9.0 to 5.10.0 allows remote attackers to read arbitrary files via .. (dot dot) sequences in an HTTP request.