Vulnerabilities > Prophecyinternational

DATE CVE VULNERABILITY TITLE RISK
2020-01-08 CVE-2011-5250 Cross-Site Request Forgery (CSRF) vulnerability in Prophecyinternational Snare
Snare for Linux before 1.7.0 has CSRF in the web interface.
network
low complexity
prophecyinternational CWE-352
6.5
2020-01-08 CVE-2011-5247 Cleartext Storage of Sensitive Information vulnerability in Prophecyinternational Snare
Snare for Linux before 1.7.0 has password disclosure because the rendered page contains the field RemotePassword.
network
low complexity
prophecyinternational CWE-312
7.5
2019-08-29 CVE-2019-11364 OS Command Injection vulnerability in Prophecyinternational Snare Central
An OS Command Injection vulnerability in Snare Central before 7.4.5 allows remote authenticated attackers to inject arbitrary OS commands via the ServerConf/DataManagement/DiskManager.php FORMNAS_share parameter.
network
low complexity
prophecyinternational CWE-78
7.2
2019-08-29 CVE-2019-11363 SQL Injection vulnerability in Prophecyinternational Snare Central
A SQL injection vulnerability in Snare Central before 7.4.5 allows remote authenticated attackers to execute arbitrary SQL commands via the AgentConsole/UserGroupQuery.php ShowUser parameter.
network
low complexity
prophecyinternational CWE-89
7.2