Vulnerabilities > Check MK Project > Check MK > 1.1.6

DATE CVE VULNERABILITY TITLE RISK
2018-07-19 CVE-2014-0243 Link Following vulnerability in Check MK Project Check MK
Check_MK through 1.2.5i2p1 allows local users to read arbitrary files via a symlink attack to a file in /var/lib/check_mk_agent/job.
local
low complexity
check-mk-project CWE-59
5.5
2015-08-31 CVE-2014-2332 Improper Input Validation vulnerability in Check MK Project Check MK
Check_MK before 1.2.2p3 and 1.2.3x before 1.2.3i5 allows remote authenticated users to delete arbitrary files via a request to an unspecified link, related to "Insecure Direct Object References." NOTE: this can be exploited by remote attackers by leveraging CVE-2014-2330.
network
low complexity
check-mk-project CWE-20
5.5
2015-08-31 CVE-2014-2331 Code Injection vulnerability in Check MK Project Check MK
Check_MK 1.2.2p2, 1.2.2p3, and 1.2.3i5 allows remote authenticated users to execute arbitrary Python code via a crafted rules.mk file in a snapshot.
8.5
2015-08-31 CVE-2014-2330 Cross-Site Request Forgery (CSRF) vulnerability in Check MK Project Check MK
Multiple cross-site request forgery (CSRF) vulnerabilities in the Multisite GUI in Check_MK before 1.2.5i2 allow remote attackers to hijack the authentication of users for requests that (1) upload arbitrary snapshots, (2) delete arbitrary files, or possibly have other unspecified impact via unknown vectors.
6.8
2015-08-31 CVE-2014-2329 Cross-site Scripting vulnerability in Check MK Project Check MK
Multiple cross-site scripting (XSS) vulnerabilities in Check_MK before 1.2.2p3 and 1.2.3x before 1.2.3i5 allow remote authenticated users to inject arbitrary web script or HTML via the (1) agent string for a check_mk agent, a (2) crafted request to a monitored host, which is not properly handled by the logwatch module, or other unspecified vectors.
3.5