Home/Product/sysax multi server
Product

sysax multi server

12 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2023-54337
all versions
Sysax Multi Server 6.95 contains a denial of service vulnerability in the administrative password field that allows attackers to c
9.1CRITICAL
CVE-2012-10060
< 5.55
Sysax Multi Server versions prior to 5.55 contain a stack-based buffer overflow in its SSH service. When a remote attacker supplie
9.8CRITICAL
CVE-2013-10065
all versions
A denial-of-service vulnerability exists in Sysax Multi-Server version 6.10 via its SSH daemon. A specially crafted SSH key excha
7.5HIGH
CVE-2024-53458
all versions
Sysax Multi Server 6.99 is vulnerable to a denial of service (DoS) condition when processing specially crafted SSH packets.
7.5HIGH
CVE-2024-53459
all versions
Sysax Multi Server 6.99 is vulnerable to Cross Site Scripting (XSS) via the /scgi?sid parameter.
5.4MEDIUM
CVE-2020-23574
all versions
When uploading a file in Sysax Multi Server 6.90, an authenticated user can modify the filename="" parameter in the uploadfile_nam
6.5MEDIUM
CVE-2020-13229
all versions
An issue was discovered in Sysax Multi Server 6.90. A session can be hijacked if one observes the sid value in any /scgi URI, beca
8.8HIGH
CVE-2020-13228
all versions
An issue was discovered in Sysax Multi Server 6.90. There is reflected XSS via the /scgi sid parameter.
6.1MEDIUM
CVE-2020-13227
all versions
An issue was discovered in Sysax Multi Server 6.90. An attacker can determine the username (under which the web server is running)
5.3MEDIUM
CVE-2012-6530
<= 5.50
Stack-based buffer overflow in Sysax Multi Server before 5.52, when HTTP is enabled, allows remote authenticated users with the cr
CVE-2009-4800
all versions
Directory traversal vulnerability in Sysax Multi Server 4.3 and 4.5 allows remote authenticated users to delete arbitrary files vi
CVE-2009-4790
all versions
Multiple directory traversal vulnerabilities in Sysax Multi Server 4.5 allow remote authenticated users to read or modify arbitrar
threatengine.sh