Vulnerabilities > Zevenet

DATE CVE VULNERABILITY TITLE RISK
2020-04-02 CVE-2020-11491 Path Traversal vulnerability in Zevenet ZEN Load Balancer 3.10.1
Monitoring::Logs in Zen Load Balancer 3.10.1 allows remote authenticated admins to conduct absolute path traversal attacks, as demonstrated by a filelog=/etc/shadow request to index.cgi.
network
low complexity
zevenet CWE-22
4.0
2020-04-02 CVE-2020-11490 OS Command Injection vulnerability in Zevenet ZEN Load Balancer 3.10.1
Manage::Certificates in Zen Load Balancer 3.10.1 allows remote authenticated admins to execute arbitrary OS commands via shell metacharacters in the index.cgi cert_issuer, cert_division, cert_organization, cert_locality, cert_state, cert_country, or cert_email parameter.
network
low complexity
zevenet CWE-78
critical
9.0
2019-02-01 CVE-2019-7301 OS Command Injection vulnerability in Zevenet ZEN Load Balancer 3.10.1
Zen Load Balancer 3.10.1 allows remote authenticated admin users to execute arbitrary commands as root via shell metacharacters in the index.cgi?action=View_Cert certname parameter.
network
low complexity
zevenet CWE-78
critical
9.0