Vulnerabilities > Filerun

DATE CVE VULNERABILITY TITLE RISK
2023-12-22 CVE-2022-47532 SQL Injection vulnerability in Filerun 20220519
FileRun 20220519 allows SQL Injection via the "dir" parameter in a /?module=users&section=cpanel&page=list request.
network
low complexity
filerun CWE-89
critical
9.8
2017-09-30 CVE-2017-14738 SQL Injection vulnerability in Filerun 2017.09.18
FileRun (version 2017.09.18 and below) suffers from a remote SQL injection vulnerability due to a failure to sanitize input in the metafield parameter inside the metasearch module (under the search function).
network
low complexity
filerun CWE-89
7.5
2007-05-02 CVE-2007-2470 Cross-Site Scripting vulnerability in FileRun
Multiple cross-site scripting (XSS) vulnerabilities in index.php in FileRun 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) page, (2) module, or (3) section parameter.
network
filerun
5.8
2007-05-02 CVE-2007-2469 SQL Injection and Cross-Site Scripting vulnerability in FileRun
SQL injection vulnerability in index.php in FileRun 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the fid parameter.
network
low complexity
filerun
7.5