Vulnerabilities > EVE NG
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-10-20 | CVE-2022-31366 | Unrestricted Upload of File with Dangerous Type vulnerability in Eve-Ng 2.0.3112 An arbitrary file upload vulnerability in the apiImportLabs function in api_labs.php of EVE-NG 2.0.3-112 Community allows attackers to execute arbitrary code via a crafted UNL file. | 7.2 |
2022-05-04 | CVE-2022-27903 | OS Command Injection vulnerability in Eve-Ng 2.0.3112/4.0.165 An OS Command Injection vulnerability in the configuration parser of Eve-NG Professional through 4.0.1-65 and Eve-NG Community through 2.0.3-112 allows a remote authenticated attacker to execute commands as root by editing virtualization command parameters of imported UNL files. | 8.8 |