Vulnerabilities > Liftoffsoftware > Gateone

DATE CVE VULNERABILITY TITLE RISK
2020-12-27 CVE-2020-35736 Path Traversal vulnerability in Liftoffsoftware Gateone 1.1
GateOne 1.1 allows arbitrary file download without authentication via /downloads/..
network
low complexity
liftoffsoftware CWE-22
7.5
2020-12-14 CVE-2020-20184 OS Command Injection vulnerability in Liftoffsoftware Gateone
GateOne allows remote attackers to execute arbitrary commands via shell metacharacters in the port field when attempting an SSH connection.
network
low complexity
liftoffsoftware CWE-78
critical
9.8