3 results (0.006 seconds)

CVSS: 9.0EPSS: 4%CPEs: 1EXPL: 2

20 Jan 2023 — jc21 NGINX Proxy Manager through 2.9.19 allows OS command injection. When creating an access list, the backend builds an htpasswd file with crafted username and/or password input that is concatenated without any validation, and is directly passed to the exec command, potentially allowing an authenticated attacker to execute arbitrary commands on the system. NOTE: this is not part of any NGINX software shipped by F5. • https://advisory.dw1.io/57 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVSS: 6.8EPSS: 0%CPEs: 1EXPL: 1

03 Apr 2022 — jc21.com Nginx Proxy Manager before 2.9.17 allows XSS during item deletion. jc21.com Nginx Proxy Manager versiones anteriores a 2.9.17, permite una vulnerabilidad de tipo XSS durante la eliminación de elementos • https://github.com/NginxProxyManager/nginx-proxy-manager/issues/1950 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 0

23 Aug 2019 — jc21 Nginx Proxy Manager before 2.0.13 allows %2e%2e%2f directory traversal. jc21 Nginx Proxy Manager anterior de la versión 2.0.13 permite el recorrido del directorio% 2e% 2e% 2f. • https://github.com/jc21/nginx-proxy-manager/compare/2.0.12...2.0.13 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •