Nchsoftware

    Dashboard / Vendors

    Products: 8
    Vulnerabilities: 34
    Known Exploited: 0
    0
    Critical Level Threats
    5
    High Level Threats
    29
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2021-37442

    NCH IVM Attendant v5.12 and earlier allows path traversal via viewfile?file=/.. to read files.

    Last Modified: Nov 21, 2024
    Published: Jul 25, 2021

    CVE-2021-37443

    NCH IVM Attendant v5.12 and earlier allows path traversal via the logdeleteselected check0 parameter for file deletion.

    Last Modified: Nov 21, 2024
    Published: Jul 25, 2021

    CVE-2021-37444

    NCH IVM Attendant v5.12 and earlier suffers from a directory traversal weakness upon uploading plugins in a ZIP archive. This can lead to code execution if a ZIP element's pathname is set to a Windows startup folder, a file for the inbuilt Out-Going Message function, or a file for the the inbuilt Autodial function.

    Last Modified: Nov 21, 2024
    Published: Jul 25, 2021

    CVE-2021-37445

    In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via logprop?file=/.. for file reading.

    Last Modified: Nov 21, 2024
    Published: Jul 25, 2021

    CVE-2021-37446

    In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via documentprop?file=/.. for file reading.

    Last Modified: Nov 21, 2024
    Published: Jul 25, 2021
    Items Per Page