Vulnerabilities > Nedi > High

DATE CVE VULNERABILITY TITLE RISK
2021-02-12 CVE-2021-26752 OS Command Injection vulnerability in Nedi 1.9C
NeDi 1.9C allows an authenticated user to execute operating system commands in the Nodes Traffic function on the endpoint /Nodes-Traffic.php via the md or ag HTTP GET parameter.
network
low complexity
nedi CWE-78
8.8
2021-02-12 CVE-2021-26751 SQL Injection vulnerability in Nedi 1.9C
NeDi 1.9C allows an authenticated user to perform a SQL Injection in the Monitoring History function on the endpoint /Monitoring-History.php via the det HTTP GET parameter.
network
low complexity
nedi CWE-89
8.8
2020-06-29 CVE-2020-14414 OS Command Injection vulnerability in Nedi 1.9C
NeDi 1.9C is vulnerable to Remote Command Execution.
network
low complexity
nedi CWE-78
8.8
2020-06-29 CVE-2020-14412 OS Command Injection vulnerability in Nedi 1.9C
NeDi 1.9C is vulnerable to Remote Command Execution.
network
low complexity
nedi CWE-78
8.8
2019-01-17 CVE-2018-20730 SQL Injection vulnerability in Nedi
A SQL injection vulnerability in NeDi before 1.7Cp3 allows any user to execute arbitrary SQL read commands via the query.php component.
network
low complexity
nedi CWE-89
7.5
2019-01-17 CVE-2018-20728 Cross-Site Request Forgery (CSRF) vulnerability in Nedi
A cross site request forgery (CSRF) vulnerability in NeDi before 1.7Cp3 allows remote attackers to escalate privileges via User-Management.php.
network
low complexity
nedi CWE-352
8.8
2019-01-17 CVE-2018-20727 OS Command Injection vulnerability in Nedi
Multiple command injection vulnerabilities in NeDi before 1.7Cp3 allow authenticated users to execute code on the server side via the flt parameter to Nodes-Traffic.php, the dv parameter to Devices-Graph.php, or the tit parameter to drawmap.php.
network
low complexity
nedi CWE-78
8.8