|
246411
|
6.1 |
MEDIUM
Network
|
totolink
|
a3002ru_firmware
|
Password disclosure in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to obtain the plaintext password for the admin user by making a GET request for password.htm.
|
CWE-79
Cross-site Scripting
|
CVE-2018-13317
|
2024-11-21 12:46 |
2018-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246412
|
9.8 |
CRITICAL
Network
|
totolink
|
a3002ru_firmware
|
Incorrect access control in formPasswordSetup in TOTOLINK A3002RU version 1.0.8 allows attackers to change the admin user's password via an unauthenticated POST request.
|
CWE-20
Improper Input Validation
|
CVE-2018-13315
|
2024-11-21 12:46 |
2018-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246413
|
6.1 |
MEDIUM
Network
|
totolink
|
a3002ru_firmware
|
Cross-site scripting in notice_gen.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript by modifying the "Input your notice URL" field.
|
CWE-79
Cross-site Scripting
|
CVE-2018-13312
|
2024-11-21 12:46 |
2018-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246414
|
9.8 |
CRITICAL
Network
|
totolink
|
a3002ru_firmware
|
System command injection in formDlna in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "sambaUser" POST parameter.
|
CWE-78
OS Command
|
CVE-2018-13311
|
2024-11-21 12:46 |
2018-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246415
|
6.1 |
MEDIUM
Network
|
totolink
|
a3002ru_firmware
|
Cross-site scripting in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript via the user's username.
|
CWE-79
Cross-site Scripting
|
CVE-2018-13310
|
2024-11-21 12:46 |
2018-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246416
|
6.1 |
MEDIUM
Network
|
totolink
|
a3002ru_firmware
|
Cross-site scripting in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript via the user's password.
|
CWE-79
Cross-site Scripting
|
CVE-2018-13309
|
2024-11-21 12:46 |
2018-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246417
|
6.1 |
MEDIUM
Network
|
totolink
|
a3002ru_firmware
|
Cross-site scripting in notice_gen.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript by modifying the "User phrases button" field.
|
CWE-79
Cross-site Scripting
|
CVE-2018-13308
|
2024-11-21 12:46 |
2018-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246418
|
6.3 |
MEDIUM
Network
|
synology
|
photo_station
|
Session fixation vulnerability in SYNO.PhotoStation.Auth in Synology Photo Station before 6.8.7-3481 allows remote attackers to hijack web sessions via the PHPSESSID parameter.
|
CWE-384
Session Fixation
|
CVE-2018-13282
|
2024-11-21 12:46 |
2018-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246419
|
4.3 |
MEDIUM
Network
|
synology
|
skynas diskstation_manager vs960hd
|
Information exposure vulnerability in SYNO.Core.ACL in Synology DiskStation Manager (DSM) before 6.2-23739-2 allows remote authenticated users to determine the existence and obtain the metadata of ar…
|
CWE-200
Information Exposure
|
CVE-2018-13281
|
2024-11-21 12:46 |
2018-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246420
|
9.8 |
CRITICAL
Network
|
linhandante
|
anda
|
The server API in the Anda app relies on hardcoded credentials.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2018-13342
|
2024-11-21 12:46 |
2018-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|