|
309261
|
5.9 |
MEDIUM
Network
|
planet
|
gs-4210-24p2s_firmware gs-4210-24pl4c_firmware igs-5225-4up1t2s_firmware
|
The swctrl service is used to detect and remotely manage PLANET Technology devices. For certain switch models, the authentication tokens used during communication with this service are encoded user p…
|
CWE-326
Inadequate Encryption Strength
|
CVE-2024-8455
|
2024-10-4 23:45 |
2024-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309262
|
4.9 |
MEDIUM
Network
|
planet
|
gs-4210-24p2s_firmware gs-4210-24pl4c_firmware
|
Certain switch models from PLANET Technology store SNMPv3 users' passwords in plaintext within the configuration files, allowing remote attackers with administrator privileges to read the file and ob…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2024-8459
|
2024-10-4 23:42 |
2024-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309263
|
8.8 |
HIGH
Network
|
planet
|
gs-4210-24p2s_firmware gs-4210-24pl4c_firmware
|
Certain switch models from PLANET Technology have a web application that is vulnerable to Cross-Site Request Forgery (CSRF). An unauthenticated remote attacker can trick a user into visiting a malici…
|
CWE-352
Origin Validation Error
|
CVE-2024-8458
|
2024-10-4 23:42 |
2024-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309264
|
7.5 |
HIGH
Network
|
echostar
|
fusion
|
Credentials to access device configuration were transmitted using an unencrypted protocol. These credentials would allow read-only access to network configuration information and terminal configurati…
|
NVD-CWE-noinfo
|
CVE-2024-42495
|
2024-10-4 23:37 |
2024-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309265
|
4.6 |
MEDIUM
Physics
|
echostar
|
fusion
|
Credentials to access device configuration information stored unencrypted in flash memory. These credentials would allow read-only access to network configuration information and terminal configurati…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2024-39278
|
2024-10-4 23:36 |
2024-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309266
|
- |
|
-
|
-
|
Scriptcase v9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_zip function.
|
-
|
CVE-2024-46080
|
2024-10-4 22:51 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309267
|
- |
|
-
|
-
|
A vulnerability classified as problematic has been found in OFCMS 1.1.2. This affects the function add of the file /admin/system/dict/add.json?sqlid=system.dict.save. The manipulation of the argument…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9411
|
2024-10-4 22:51 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309268
|
- |
|
-
|
-
|
Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious payloads using the messages feature, which allows the injection of malicious cod…
|
-
|
CVE-2024-46083
|
2024-10-4 22:51 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309269
|
- |
|
-
|
-
|
Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious payloads in the To-Do List. The assigned user will trigger a stored XSS, which i…
|
-
|
CVE-2024-46081
|
2024-10-4 22:51 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309270
|
- |
|
-
|
-
|
Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS) in proj_new.php via the Descricao parameter.
|
-
|
CVE-2024-46079
|
2024-10-4 22:51 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|