Home/Product/titanhq webtitan
Product

titanhq webtitan

13 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2019-19021
< 5.18
An issue was discovered in TitanHQ WebTitan before 5.18. It has a hidden support account (with a hard-coded password) in the web a
9.8CRITICAL
CVE-2019-19020
< 5.18
An issue was discovered in TitanHQ WebTitan before 5.18. In the administration web interface it is possible to upload a crafted ba
7.2HIGH
CVE-2019-19019
< 5.18
An issue was discovered in TitanHQ WebTitan before 5.18. It contains a Remote Code Execution issue through which an attacker can e
7.5HIGH
CVE-2019-19018
< 5.18
An issue was discovered in TitanHQ WebTitan before 5.18. It exposes a database configuration file under /include/dbconfig.ini in t
2.7LOW
CVE-2019-19017
< 5.18
An issue was discovered in TitanHQ WebTitan before 5.18. The appliance has a hard-coded root password set during installation. An
8.1HIGH
CVE-2019-19016
< 5.18
An issue was discovered in TitanHQ WebTitan before 5.18. Some functions, such as /history-x.php, of the administration interface a
7.5HIGH
CVE-2019-19015
< 5.18
An issue was discovered in TitanHQ WebTitan before 5.18. The proxy service (which is typically exposed to all users) allows connec
9.8CRITICAL
CVE-2019-19014
< 5.18
An issue was discovered in TitanHQ WebTitan before 5.18. It has a sudoers file that enables low-privilege users to execute a vast
7.8HIGH
CVE-2014-4307
<= 4.01
SQL injection vulnerability in categories-x.php in WebTitan before 4.04 allows remote attackers to execute arbitrary SQL commands
CVE-2014-4306
<= 4.01
Directory traversal vulnerability in logs-x.php in WebTitan before 4.04 allows remote attackers to read arbitrary files via a .. (
CVE-2011-4640
<= 3.50
Directory traversal vulnerability in logs-x.php in SpamTitan WebTitan before 3.60 allows remote authenticated users to read arbitr
CVE-2011-4639
<= 3.50
The (1) Traceroute and (2) Ping implementations in tools.php in SpamTitan WebTitan before 3.60 allow remote authenticated users to
CVE-2011-4638
<= 3.50
Multiple SQL injection vulnerabilities in SpamTitan WebTitan before 3.60 allow remote attackers to execute arbitrary SQL commands
threatengine.sh