Vulnerabilities (CVE)

Filtered by vendor Zucchetti Subscribe
Filtered by product Ad Hoc Infinity
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-51319 1 Zucchetti 1 Ad Hoc Infinity 2025-05-28 N/A 7.3 HIGH
A local file include vulnerability in the /servlet/Report of Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote Code Execution by uploading a jsp web/reverse shell through /jsp/zimg_upload.jsp.
CVE-2024-51320 1 Zucchetti 1 Ad Hoc Infinity 2025-05-28 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability in Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote Code Execution via the /servlet/gsdm_fsave_htmltmp, /servlet/gsdm_btlk_openfile components
CVE-2024-51321 1 Zucchetti 1 Ad Hoc Infinity 2025-05-28 N/A 7.6 HIGH
In Zucchetti Ad Hoc Infinity 2.4, an improper check on the m_cURL parameter allows an attacker to redirect the victim to an attacker-controlled website after the authentication.