Vulnerabilities > Xymon > High

DATE CVE VULNERABILITY TITLE RISK
2016-04-13 CVE-2016-2056 Command Injection vulnerability in multiple products
xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote authenticated users to execute arbitrary commands via shell metacharacters in the adduser_name argument in (1) web/useradm.c or (2) web/chpasswd.c.
network
low complexity
xymon debian CWE-77
8.8
2016-04-13 CVE-2016-2055 Information Exposure vulnerability in multiple products
xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to read arbitrary files in the configuration directory via a "config" command.
network
low complexity
xymon debian CWE-200
7.5