Klog Server

Vendor:

First CVE: Dec 27, 2020 · Active for 5 years

2
Total CVEs
More Total CVEs than 49% of tracked products
1.0
Avg CVEs / Year
Bottom 1%
9.3
Avg CVSS
Higher Avg CVSS than 85% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Klog Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 27, 2020
5 years ago
Most Recent CVE
Jan 26, 2021
2,005 days ago

CVE Severity & Scoring

Klog Server2 CVEs
All CVEs352,231 CVEs
HighCritical
Attack Vector
Local0 (0.0%)
Network2 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low1 (50.0%)
High0 (0.0%)
None1 (50.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (2 CVEs).

2 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.
Dec 27, 20209.891NOYES
KLog Server through 2.4.1 allows authenticated command injection. async.php calls shell_exec() on the original value of the source parameter.
Jan 26, 20218.859NOYES

Exploit Exposure

Signals from CVEs in this product scope (2 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
50.0% of CVEs· 98th percentile
Nuclei
1 CVE
50.0% of CVEs· 98th percentile
ExploitDB
2 CVEs
100.0% of CVEs· 93rd percentile

Social Chatter

Signals from CVEs in this product scope (2 CVEs).

Media Mentions

Signals from CVEs in this product scope (2 CVEs).

Top CNAs Publishing CVEs For Klog Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.4.119.888.0%01