Meteocontrol

    Dashboard / Vendors

    Products: 5
    Vulnerabilities: 4
    Known Exploited: 0
    3
    Critical Level Threats
    1
    High Level Threats
    0
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2016-4504

    A Cross-Site Request Forgery issue was discovered in Meteocontrol WEB'log Basic 100 all versions, Light all versions, Pro all versions, and Pro Unlimited all versions. There is no CSRF Token generated per page or per function.

    Last Modified: Apr 20, 2025
    Published: Mar 21, 2017

    CVE-2016-2297

    Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited allows remote attackers to execute arbitrary commands via an "access command shell-like feature."

    Last Modified: Apr 12, 2025
    Published: May 14, 2016

    CVE-2016-2296

    Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited does not require authentication for "post-admin" login pages, which allows remote attackers to obtain sensitive information or modify data via unspecified vectors.

    Last Modified: Apr 12, 2025
    Published: May 14, 2016

    CVE-2016-2298

    Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited allows remote attackers to obtain sensitive cleartext information via unspecified vectors.

    Last Modified: Apr 12, 2025
    Published: May 14, 2016
    Items Per Page
    Meteocontrol Vulnerabilities & Security CVEs | CVE-DB