Vulnerabilities > Xorux > Critical
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-11-08 | CVE-2021-42371 | Insecure Storage of Sensitive Information vulnerability in Xorux Lpar2Rrd and Stor2Rrd lpar2rrd is a hardcoded system account in XoruX LPAR2RRD and STOR2RRD before 7.30. | 9.8 |
2020-08-18 | CVE-2020-24032 | OS Command Injection vulnerability in Xorux Lpar2Rrd and Stor2Rrd tz.pl on XoruX LPAR2RRD and STOR2RRD 2.70 virtual appliances allows cmd=set&tz=OS command injection via shell metacharacters in a timezone. | 9.8 |
2020-02-17 | CVE-2014-4981 | OS Command Injection vulnerability in Xorux Lpar2Rrd LPAR2RRD in 3.5 and earlier allows remote attackers to execute arbitrary commands due to insufficient input sanitization of the web GUI parameters. | 9.8 |
2020-01-10 | CVE-2014-4982 | Command Injection vulnerability in Xorux Lpar2Rrd LPAR2RRD = 4.53 and = 3.5 has arbitrary command injection on the application server. | 9.8 |