VendorsProphecy Internationalsnare_centralany version
Vulnerabilities

Prophecy International Snare Central any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2019-11364
An OS Command Injection vulnerability in Snare Central before 7.4.5 allows remote authenticated attackers to inject arbitrary OS commands via the ServerConf/DataManagement/DiskManager.php FORMNAS_share parameter.
Published 2019-08-29 · Modified
9.0EPSS 0.022
CVE-2019-11363
A SQL injection vulnerability in Snare Central before 7.4.5 allows remote authenticated attackers to execute arbitrary SQL commands via the AgentConsole/UserGroupQuery.php ShowUser parameter.
Published 2019-08-29 · Modified
7.2EPSS 0.011