|
246021
|
9.8 |
CRITICAL
Network
|
d-link
|
dir-823g_firmware
|
On D-Link DIR-823G devices, the GoAhead configuration allows /HNAP1 Command Injection via shell metacharacters in the POST data, because this data is sent directly to the "system" library function.
|
CWE-78
OS Command
|
CVE-2018-17787
|
2024-11-21 12:54 |
2018-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246022
|
9.8 |
CRITICAL
Network
|
d-link
|
dir-823g_firmware
|
On D-Link DIR-823G devices, ExportSettings.sh, upload_settings.cgi, GetDownLoadSyslog.sh, and upload_firmware.cgi do not require authentication, which allows remote attackers to execute arbitrary cod…
|
CWE-287
Improper Authentication
|
CVE-2018-17786
|
2024-11-21 12:54 |
2018-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246023
|
6.1 |
MEDIUM
Network
|
zohocorp
|
manageengine_assetexplorer
|
In Zoho ManageEngine AssetExplorer, a Stored XSS vulnerability was discovered in the 6.2.0 version via the /AssetDef.do ciName or assetName parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17596
|
2024-11-21 12:54 |
2018-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246024
|
6.1 |
MEDIUM
Network
|
fork-cms
|
fork_cms
|
In the 5.4.0 version of the Fork CMS software, HTML Injection and Stored XSS vulnerabilities were discovered via the /backend/ajax URI.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17595
|
2024-11-21 12:54 |
2018-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246025
|
6.1 |
MEDIUM
Network
|
airties
|
air_5443v2_firmware
|
AirTies Air 5443v2 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17594
|
2024-11-21 12:54 |
2018-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246026
|
6.1 |
MEDIUM
Network
|
airties
|
air_5453_firmware
|
AirTies Air 5453 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17593
|
2024-11-21 12:54 |
2018-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246027
|
6.1 |
MEDIUM
Network
|
airties
|
air_5343v2_firmware
|
AirTies Air 5343v2 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17591
|
2024-11-21 12:54 |
2018-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246028
|
6.1 |
MEDIUM
Network
|
airties
|
air_5442_firmware
|
AirTies Air 5442 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17590
|
2024-11-21 12:54 |
2018-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246029
|
6.1 |
MEDIUM
Network
|
airties
|
air_5650_firmware
|
AirTies Air 5650 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17589
|
2024-11-21 12:54 |
2018-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246030
|
6.1 |
MEDIUM
Network
|
airties
|
air_5021_firmware
|
AirTies Air 5021 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17588
|
2024-11-21 12:54 |
2018-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|