Aidaho
9 exploits
Active since Mar 2023
Roxy-WI: Path-traversal patch in commit d4d10006 is a no-op (tuple-membership bug)
CVSS 8.1
Roxy-WI vulnerable to path traversal and arbitrary file writing
CVSS 9.8
Roxy-WI <8.2.6.4 oldconfig - Arbitrary File Read
CVSS 7.5
Roxy-WI has SQL Injection in haproxy_section_save Endpoint via Unsanitized server_ip Parameter
CVSS 9.8
Roxy-WI Vulnerable to Authenticated Remote Code Execution via OS Command Injection in find-in-config Endpoint
CVSS 8.8
Roxy-WI Vulnerable to Authenticated Arbitrary File Read via Path Traversal in Config Version Viewer
CVSS 6.5
Roxy-WI <8.2.6.3 Config Compare - Authenticated Command Injection
CVSS 8.8
roxy-wi < 6.3.6.0 - Path Traversal via Directory Traversal Sequences
CVSS 7.5
Roxy-WI <8.2.8.2 - Command Injection
CVSS 7.5