Vulnerabilities > Inclusion of Functionality from Untrusted Control Sphere

DATE CVE VULNERABILITY TITLE RISK
2021-07-09 CVE-2021-30121 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Kaseya VSA
Semi-authenticated local file inclusion The contents of arbitrary files can be returned by the webserver Example request: `https://x.x.x.x/KLC/js/Kaseya.SB.JS/js.aspx?path=C:\Kaseya\WebPages\dl.asp` A valid sessionId is required but can be easily obtained via CVE-2021-30118
network
low complexity
kaseya CWE-829
6.5
2021-06-24 CVE-2021-29777 Inclusion of Functionality from Untrusted Control Sphere vulnerability in IBM DB2
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5, under specific circumstance of a table being dropped while being accessed in another session, could allow an authenticated user to cause a denial of srevice IBM X-Force ID: 203031.
network
low complexity
ibm CWE-829
6.5
2021-06-17 CVE-2020-25414 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Monstra 3.0.4
A local file inclusion vulnerability was discovered in the captcha function in Monstra 3.0.4 which allows remote attackers to execute arbitrary PHP code.
network
low complexity
monstra CWE-829
critical
9.8
2021-06-17 CVE-2021-3603 Inclusion of Functionality from Untrusted Control Sphere vulnerability in multiple products
PHPMailer 6.4.1 and earlier contain a vulnerability that can result in untrusted code being called (if such code is injected into the host project's scope by other means).
network
high complexity
phpmailer-project fedoraproject CWE-829
8.1
2021-06-04 CVE-2021-30507 Inclusion of Functionality from Untrusted Control Sphere vulnerability in multiple products
Inappropriate implementation in Offline in Google Chrome on Android prior to 90.0.4430.212 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.
network
low complexity
google fedoraproject CWE-829
8.8
2021-06-01 CVE-2020-4561 Inclusion of Functionality from Untrusted Control Sphere vulnerability in multiple products
IBM Cognos Analytics 11.0 and 11.1 DQM API allows submitting of all control requests in unauthenticated sessions.
network
low complexity
ibm netapp CWE-829
critical
10.0
2021-03-15 CVE-2020-24985 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Quadbase Espressdashboard 7.0
An issue was discovered in Quadbase EspressReports ES 7 Update 9.
network
low complexity
quadbase CWE-829
8.1
2021-03-12 CVE-2021-28162 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Eclipse Theia
In Eclipse Theia versions up to and including 0.16.0, in the notification messages there is no HTML escaping, so Javascript code can run.
network
low complexity
eclipse CWE-829
6.1
2021-02-22 CVE-2020-22474 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Weberp 4.15
In webERP 4.15, the ManualContents.php file allows users to specify the "Language" parameter, which can lead to local file inclusion.
network
low complexity
weberp CWE-829
6.5
2021-02-18 CVE-2021-20443 Inclusion of Functionality from Untrusted Control Sphere vulnerability in IBM Maximo for Civil Infrastructure 7.6.2
IBM Maximo for Civil Infrastructure 7.6.2 includes executable functionality (such as a library) from a source that is outside of the intended control sphere.
network
low complexity
ibm CWE-829
8.8