VendorsElement-IThttp_commander5.3.3
Vulnerabilities

Element-IT Software HTTP Commander 5.3.3

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2021-33211
A Directory Traversal vulnerability in the Unzip feature in Elements-IT HTTP Commander 5.3.3 allows remote authenticated users to write files to arbitrary directories via relative paths in ZIP archives.
Published 2021-07-14 · Modified
6.5EPSS 0.017
CVE-2021-33213
An SSRF vulnerability in the "Upload from URL" feature in Elements-IT HTTP Commander 5.3.3 allows remote authenticated users to retrieve HTTP and FTP files from the internal server network by inserting an internal address.
Published 2021-07-14 · Modified
6.5EPSS 0.013
CVE-2021-33212
A Cross-site scripting (XSS) vulnerability in the "View in Browser" feature in Elements-IT HTTP Commander 5.3.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted SVG image.
Published 2021-07-14 · Modified
5.4EPSS 0.007