Gary Allan

15 exploits Active since Dec 2018
CVE-2018-1000869 WRITEUP CRITICAL WRITEUP
phpIPAM <1.3.2 - SQL Injection
phpIPAM version 1.3.2 contains a CWE-89 vulnerability in /app/admin/nat/item-add-submit.php that can result in SQL Injection.. This attack appear to be exploitable via Rough user, exploiting the vulnerability to access information he/she does not have access to.. This vulnerability appears to have been fixed in 1.4.
CVSS 9.8
CVE-2018-1000870 WRITEUP MEDIUM WRITEUP
PHPipam <1.3.2 - RCE
PHPipam version 1.3.2 and earlier contains a CWE-79 vulnerability in /app/admin/users/print-user.php that can result in Execute code in the victims browser. This attack appear to be exploitable via Attacker change theme parameter in user settings. Admin(Victim) views user in admin-panel and gets exploited.. This vulnerability appears to have been fixed in 1.4.
CVSS 5.4
CVE-2019-1000010 WRITEUP MEDIUM WRITEUP
phpIPAM <1.3.2 - XSS
phpIPAM version 1.3.2 and earlier contains a Cross Site Scripting (XSS) vulnerability in subnet-scan-telnet.php that can result in executing code in victims browser. This attack appears to be exploitable via victim visits link crafted by an attacker. This vulnerability appears to have been fixed in 1.4.
CVSS 6.1
CVE-2022-1223 WRITEUP MEDIUM WRITEUP
Phpipam < 1.4.6 - Incorrect Authorization
Incorrect Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.
CVSS 6.5
CVE-2022-1224 WRITEUP MEDIUM WRITEUP
Phpipam < 1.4.6 - Incorrect Authorization
Improper Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.
CVSS 6.5
CVE-2022-1225 WRITEUP MEDIUM WRITEUP
Phpipam < 1.4.6 - Incorrect Privilege Assignment
Incorrect Privilege Assignment in GitHub repository phpipam/phpipam prior to 1.4.6.
CVSS 6.5
CVE-2022-1226 WRITEUP MEDIUM WRITEUP
Phpipam < 1.4.7 - XSS
A Cross-Site Scripting (XSS) vulnerability in phpipam/phpipam versions prior to 1.4.7 allows attackers to execute arbitrary JavaScript code in the browser of a victim. This vulnerability affects the import Data set feature via a spreadsheet file upload. The affected endpoints include import-vlan-preview.php, import-subnets-preview.php, import-vrf-preview.php, import-ipaddr-preview.php, import-devtype-preview.php, import-devices-preview.php, and import-l2dom-preview.php. The vulnerability can be exploited by uploading a specially crafted spreadsheet file containing malicious JavaScript payloads, which are then executed in the context of the victim's browser. This can lead to defacement of websites, execution of malicious JavaScript code, stealing of user cookies, and unauthorized access to user accounts.
CVSS 4.8
CVE-2022-3845 WRITEUP LOW WRITEUP
phpipam <1.5.0 - XSS
A vulnerability has been found in phpipam and classified as problematic. Affected by this vulnerability is an unknown functionality of the file app/admin/import-export/import-load-data.php of the component Import Preview Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. Upgrading to version 1.5.0 is able to address this issue. The name of the patch is 22c797c3583001211fe7d31bccd3f1d4aeeb3bbc. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-212863.
CVSS 2.4
CVE-2023-0676 WRITEUP MEDIUM WRITEUP
Phpipam < 1.5.1 - XSS
Cross-site Scripting (XSS) - Reflected in GitHub repository phpipam/phpipam prior to 1.5.1.
CVSS 6.1
CVE-2023-0677 WRITEUP MEDIUM WRITEUP
Phpipam < 1.5.1 - XSS
Cross-site Scripting (XSS) - Reflected in GitHub repository phpipam/phpipam prior to v1.5.1.
CVSS 6.1
CVE-2023-0678 WRITEUP MEDIUM WRITEUP
Phpipam < 1.5.1 - Missing Authorization
Missing Authorization in GitHub repository phpipam/phpipam prior to v1.5.1.
CVSS 5.3
CVE-2023-1212 WRITEUP MEDIUM WRITEUP
Phpipam < 1.5.2 - XSS
Cross-site Scripting (XSS) - Stored in GitHub repository phpipam/phpipam prior to v1.5.2.
CVSS 4.8
CVE-2023-41580 WRITEUP HIGH WRITEUP
Phpipam <1.5.2 - Command Injection
Phpipam before v1.5.2 was discovered to contain a LDAP injection vulnerability via the dname parameter at /users/ad-search-result.php. This vulnerability allows attackers to enumerate arbitrary fields in the LDAP server and access sensitive data via a crafted POST request.
CVSS 7.5
CVE-2024-0787 WRITEUP MEDIUM WRITEUP
phpIPAM <1.5.1 - Auth Bypass
phpIPAM version 1.5.1 contains a vulnerability where an attacker can bypass the IP block mechanism to brute force passwords for users by using the 'X-Forwarded-For' header. The issue lies in the 'get_user_ip()' function in 'class.Common.php' at lines 1044 and 1045, where the presence of the 'X-Forwarded-For' header is checked and used instead of 'REMOTE_ADDR'. This vulnerability allows attackers to perform brute force attacks on user accounts, including the admin account. The issue is fixed in version 1.7.0.
CVSS 5.9
CVE-2024-10718 WRITEUP HIGH WRITEUP
Phpipam < 1.7.0 - Cleartext Transmission
In phpipam/phpipam version 1.5.1, the Secure attribute for sensitive cookies in HTTPS sessions is not set. This could cause the user agent to send those cookies in plaintext over an HTTP session, potentially exposing sensitive information. The issue is fixed in version 1.7.0.
CVSS 7.5