Apache Virtual Computing Lab vulnerabilities

3 known vulnerabilities affecting apache/virtual_computing_lab.

Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2

Vulnerabilities

Page 1 of 1
CVE-2018-11773CRITICALCVSS 9.8≥ 2.1, ≤ 2.52019-07-29
CVE-2018-11773 [CRITICAL] CWE-20 CVE-2018-11773: Apache VCL versions 2.1 through 2.5 do not properly validate form input when processing a submitted Apache VCL versions 2.1 through 2.5 do not properly validate form input when processing a submitted block allocation. The form data is then used as an argument to the php built in function strtotime. This allows for an attack against the underlying implementation of that function. The implementation of strtotime at the time the issue was discovered
nvd
CVE-2018-11772HIGHCVSS 7.2≥ 2.1, ≤ 2.52019-07-29
CVE-2018-11772 [HIGH] CWE-89 CVE-2018-11772: Apache VCL versions 2.1 through 2.5 do not properly validate cookie input when determining what node Apache VCL versions 2.1 through 2.5 do not properly validate cookie input when determining what node (if any) was previously selected in the privilege tree. The cookie data is then used in an SQL statement. This allows for an SQL injection attack. Access to this portion of a VCL system requires admin level rights. Other layers of security seem to prote
nvd
CVE-2018-11774HIGHCVSS 7.2≥ 2.1, ≤ 2.52019-07-29
CVE-2018-11774 [HIGH] CWE-89 CVE-2018-11774: Apache VCL versions 2.1 through 2.5 do not properly validate form input when adding and removing VMs Apache VCL versions 2.1 through 2.5 do not properly validate form input when adding and removing VMs to and from hosts. The form data is then used in SQL statements. This allows for an SQL injection attack. Access to this portion of a VCL system requires admin level rights. Other layers of security seem to protect against malicious attack. However, all
nvd