|
266851
|
6.5 |
MEDIUM
Network
|
buffalotech
|
wnc01wh_firmware
|
Directory traversal vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated attackers to read arbitrary files via specially crafted POST requests.
|
CWE-22
Path Traversal
|
CVE-2016-7826
|
2024-11-21 11:58 |
2017-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266852
|
6.5 |
MEDIUM
Network
|
buffalotech
|
wnc01wh_firmware
|
Directory traversal vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated attackers to read arbitrary files via specially crafted commands.
|
CWE-22
Path Traversal
|
CVE-2016-7825
|
2024-11-21 11:58 |
2017-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266853
|
8.8 |
HIGH
Network
|
buffalotech
|
wnc01wh_firmware
|
Buffalo NC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated attackers to bypass access restriction to enable the debug option via unspecified vectors.
|
CWE-284
Improper Access Control
|
CVE-2016-7824
|
2024-11-21 11:58 |
2017-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266854
|
4.3 |
MEDIUM
Adjacent
|
buffalotech
|
wnc01wh_firmware
|
Cross-site scripting vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2016-7823
|
2024-11-21 11:58 |
2017-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266855
|
8.8 |
HIGH
Network
|
buffalotech
|
wnc01wh_firmware
|
Cross-site request forgery (CSRF) vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows remote attackers to hijack the authentication of a logged in user to perfor…
|
CWE-352
Origin Validation Error
|
CVE-2016-7822
|
2024-11-21 11:58 |
2017-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266856
|
6.5 |
MEDIUM
Network
|
buffalotech
|
wnc01wh_firmware
|
Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allow remote attackers to cause a denial of service against the management screen via unspecified vectors.
|
CWE-20
Improper Input Validation
|
CVE-2016-7821
|
2024-11-21 11:58 |
2017-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266857
|
7.2 |
HIGH
Network
|
iodata
|
ts-wrlp_firmware ts-wrla_firmware
|
Buffer overflow in I-O DATA DEVICE TS-WRLP firmware version 1.01.02 and earlier and TS-WRLA firmware version 1.01.02 and earlier allows an attacker with administrator rights to cause a denial-of-serv…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-7820
|
2024-11-21 11:58 |
2017-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266858
|
7.2 |
HIGH
Network
|
iodata
|
ts-wrlp_firmware ts-wrla_firmware
|
I-O DATA DEVICE TS-WRLP firmware version 1.01.02 and earlier and TS-WRLA firmware version 1.01.02 and earlier allows an attacker with administrator rights to execute arbitrary OS commands via unspeci…
|
CWE-78
OS Command
|
CVE-2016-7819
|
2024-11-21 11:58 |
2017-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266859
|
7.8 |
HIGH
Local
|
japan_pension_service
|
todokesho_creation_program device_data_encryption_program specification_check_program todokesho_print_program
|
Untrusted search path vulnerability in Installers for Specification check program (social insurance) Ver. 9.00 and earlier, TODOKESHO print program Ver. 5.00 and earlier, Device data encryption progr…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-7818
|
2024-11-21 11:58 |
2017-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266860
|
6.1 |
MEDIUM
Network
|
simple_keitai_chat_project
|
simple_keitai_chat
|
Cross-site scripting vulnerability in Simple keitai chat 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2016-7817
|
2024-11-21 11:58 |
2017-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|