
CVE-2021-25276
https://notcve.org/view.php?id=CVE-2021-25276
03 Feb 2021 — In SolarWinds Serv-U before 15.2.2 Hotfix 1, there is a directory containing user profile files (that include users' password hashes) that is world readable and writable. An unprivileged Windows user (having access to the server's filesystem) can add an FTP user by copying a valid profile file to this directory. For example, if this profile sets up a user with a C:\ home directory, then the attacker obtains access to read or replace arbitrary files with LocalSystem privileges. En SolarWinds Serv-U versiones... • https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/full-system-control-with-new-solarwinds-orion-based-and-serv-u-ftp-vulnerabilities • CWE-732: Incorrect Permission Assignment for Critical Resource •

CVE-2021-25274
https://notcve.org/view.php?id=CVE-2021-25274
03 Feb 2021 — The Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue) and doesn't set permissions on its private queues. As a result, remote unauthenticated clients can send messages to TCP port 1801 that the Collector Service will process. Additionally, upon processing of such messages, the service deserializes them in insecure manner, allowing remote arbitrary code execution as LocalSystem. El Collector Service en SolarWinds Orion Platform versiones anteriores a 2020.2.4 u... • https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/full-system-control-with-new-solarwinds-orion-based-and-serv-u-ftp-vulnerabilities • CWE-502: Deserialization of Untrusted Data •

CVE-2021-25275
https://notcve.org/view.php?id=CVE-2021-25275
03 Feb 2021 — SolarWinds Orion Platform before 2020.2.4, as used by various SolarWinds products, installs and uses a SQL Server backend, and stores database credentials to access this backend in a file readable by unprivileged users. As a result, any user having access to the filesystem can read database login details from that file, including the login name and its associated password. Then, the credentials can be used to get database owner access to the SWNetPerfMon.DB database. This gives access to the data collected ... • https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/full-system-control-with-new-solarwinds-orion-based-and-serv-u-ftp-vulnerabilities • CWE-798: Use of Hard-coded Credentials •

CVE-2020-28001 – SolarWinds Serv-U FTP Server 15.2.1 Cross Site Scripting
https://notcve.org/view.php?id=CVE-2020-28001
03 Feb 2021 — SolarWinds Serv-U before 15.2.2 allows Authenticated Stored XSS. SolarWinds Serv-U versiones anteriores a 15.2.2, permite un ataque de tipo XSS almacenado autenticado SolarWinds Serv-U FTP Server versions through 15.2.1 do not correctly sanitize and validate the user-supplied directory names, allowing malicious users to create directories that when clicked on (in the breadcrumb menu) will trigger cross site scripting payloads. • https://packetstorm.news/files/id/161400 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2020-27994 – SolarWinds Serv-U FTP Server 15.2.1 Path Traversal
https://notcve.org/view.php?id=CVE-2020-27994
03 Feb 2021 — SolarWinds Serv-U before 15.2.2 allows Authenticated Directory Traversal. SolarWinds Serv-U versiones anteriores a 15.2.2, permite un Salto de Directorio autenticado SolarWinds Serv-U File Server versions through 15.2.1 do not correctly validate path information, allowing the disclosure of files and directories outside of the user's home directory via a specially crafted GET request. • https://packetstorm.news/files/id/161399 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2020-35482
https://notcve.org/view.php?id=CVE-2020-35482
03 Feb 2021 — SolarWinds Serv-U before 15.2.2 allows authenticated reflected XSS. SolarWinds Serv-U versiones anteriores a 15.2.2, permite un ataque de tipo XSS reflejado autenticado • https://documentation.solarwinds.com/en/success_center/servu/Content/Release_Notes/Servu_15-2-2_release_notes.htm • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2020-35481
https://notcve.org/view.php?id=CVE-2020-35481
03 Feb 2021 — SolarWinds Serv-U before 15.2.2 allows Unauthenticated Macro Injection. SolarWinds Serv-U versiones anteriores a 15.2.2, permite una Inyección de Macros no Autenticados • https://documentation.solarwinds.com/en/success_center/servu/Content/Release_Notes/Servu_15-2-2_release_notes.htm •

CVE-2019-16961
https://notcve.org/view.php?id=CVE-2019-16961
15 Jan 2021 — SolarWinds Web Help Desk 12.7.0 allows XSS via a Schedule Name. SolarWinds Web Help Desk versión 12.7.0, permite un ataque de tipo XSS por medio de un Schedule Name • https://support.solarwinds.com/SuccessCenter/s • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2019-16954
https://notcve.org/view.php?id=CVE-2019-16954
06 Jan 2021 — SolarWinds Web Help Desk 12.7.0 allows HTML injection via a Comment in a Help Request ticket. SolarWinds Web Help Desk versión 12.7.0, permite una inyección de HTML por medio de un Comentario en un ticket de Petición de Ayuda • https://support.solarwinds.com/SuccessCenter/s • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2019-16960
https://notcve.org/view.php?id=CVE-2019-16960
04 Jan 2021 — SolarWinds Web Help Desk 12.7.0 allows XSS via a CSV template file with a crafted Location Name field. SolarWinds Web Help Desk versión 12.7.0, permite un ataque de tipo XSS por medio de un archivo de plantilla CSV con un campo Location Name diseñado. • https://support.solarwinds.com/SuccessCenter/s • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •