Vulnerabilities > Inclusion of Functionality from Untrusted Control Sphere

DATE CVE VULNERABILITY TITLE RISK
2022-10-18 CVE-2022-22246 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Juniper Junos
A PHP Local File Inclusion (LFI) vulnerability in the J-Web component of Juniper Networks Junos OS may allow a low-privileged authenticated attacker to execute an untrusted PHP file.
network
low complexity
juniper CWE-829
8.8
2022-09-13 CVE-2022-37191 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Cuppacms 1.0
The component "cuppa/api/index.php" of CuppaCMS v1.0 is Vulnerable to LFI.
network
low complexity
cuppacms CWE-829
6.5
2022-07-27 CVE-2022-34121 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Cuppacms 1.0
Cuppa CMS v1.0 was discovered to contain a local file inclusion (LFI) vulnerability via the component /templates/default/html/windows/right.php.
network
low complexity
cuppacms CWE-829
7.5
2022-07-20 CVE-2022-33317 Inclusion of Functionality from Untrusted Control Sphere vulnerability in multiple products
Inclusion of Functionality from Untrusted Control Sphere vulnerability in ICONICS GENESIS64 versions 10.97.1 and prior and Mitsubishi Electric MC Works64 versions 4.04E (10.95.210.01) and prior allows an unauthenticated attacker to execute an arbitrary malicious code by leading a user to load a monitoring screen file including malicious script codes.
local
low complexity
iconics mitsubishielectric CWE-829
7.8
2022-07-15 CVE-2022-30243 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Honeywell Alterton Visual Logic Firmware
Honeywell Alerton Visual Logic through 2022-05-04 allows unauthenticated programming writes from remote users.
network
low complexity
honeywell CWE-829
8.8
2022-07-15 CVE-2022-30244 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Honeywell Alerton Ascent Control Module Firmware
Honeywell Alerton Ascent Control Module (ACM) through 2022-05-04 allows unauthenticated programming writes from remote users.
network
low complexity
honeywell CWE-829
8.0
2022-07-08 CVE-2021-41037 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Eclipse Equinox P2
In Eclipse p2, installable units are able to alter the Eclipse Platform installation and the local machine via touchpoints during installation.
network
low complexity
eclipse CWE-829
8.0
2022-05-24 CVE-2021-4229 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Ua-Parser-Js Project Ua-Parser-Js 0.7.29/0.8.0/1.0.0
A vulnerability was found in ua-parser-js 0.7.29/0.8.0/1.0.0.
network
low complexity
ua-parser-js-project CWE-829
8.8
2022-05-11 CVE-2022-29845 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Progress Whatsup Gold 21.1.0/21.1.1/22.0.0
In Progress Ipswitch WhatsUp Gold 21.1.0 through 21.1.1, and 22.0.0, it is possible for an authenticated user to invoke an API transaction that would allow them to read the contents of a local file.
network
low complexity
progress CWE-829
6.5
2022-03-15 CVE-2022-25485 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Cuppacms 1.0
CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertLightbox.php.
local
low complexity
cuppacms CWE-829
7.8