|
246371
|
5.4 |
MEDIUM
Network
|
open-xchange
|
open-xchange_appsuite
|
OX App Suite 7.8.4 and earlier allows SSRF.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2018-13103
|
2024-11-21 12:46 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246372
|
4.3 |
MEDIUM
Network
|
fortinet
|
fortiadc fortios
|
A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGa…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-13374
|
2024-11-21 12:46 |
2019-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246373
|
9.8 |
CRITICAL
Network
|
yeswiki
|
cercopitheque
|
SQL injection vulnerability in the "Bazar" page in Yeswiki Cercopitheque 2018-06-19-1 and earlier allows attackers to execute arbitrary SQL commands via the "id" parameter.
|
CWE-89
SQL Injection
|
CVE-2018-13045
|
2024-11-21 12:46 |
2019-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246374
|
5.3 |
MEDIUM
Network
|
terra-master
|
terramaster_operating_system
|
User enumeration in usertable.php in TerraMaster TOS version 3.1.03 allows attackers to list all system users via the "modgroup" parameter.
|
CWE-20
Improper Input Validation
|
CVE-2018-13361
|
2024-11-21 12:46 |
2018-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246375
|
6.1 |
MEDIUM
Network
|
terra-master
|
terramaster_operating_system
|
Cross-site scripting in Text Editor in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the "filename" URL parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-13360
|
2024-11-21 12:46 |
2018-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246376
|
8.8 |
HIGH
Network
|
terra-master
|
terramaster_operating_system
|
Cross-site scripting in usertable.php in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the "modgroup" parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-13359
|
2024-11-21 12:46 |
2018-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246377
|
8.8 |
HIGH
Network
|
terra-master
|
terramaster_operating_system
|
System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "checkName" parameter.
|
CWE-78
OS Command
|
CVE-2018-13358
|
2024-11-21 12:46 |
2018-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246378
|
5.4 |
MEDIUM
Network
|
terra-master
|
terramaster_operating_system
|
Cross-site scripting in Control Panel in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript when viewing Shared Folders via JavaScript in Shared Folders' names.
|
CWE-79
Cross-site Scripting
|
CVE-2018-13357
|
2024-11-21 12:46 |
2018-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246379
|
8.8 |
HIGH
Network
|
terra-master
|
terramaster_operating_system
|
Incorrect access control on ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to elevate user permissions.
|
CWE-863
Incorrect Authorization
|
CVE-2018-13356
|
2024-11-21 12:46 |
2018-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246380
|
6.5 |
MEDIUM
Network
|
terra-master
|
terramaster_operating_system
|
Incorrect access controls in ajaxdata.php in TerraMaster TOS version 3.1.03 allow attackers to create user groups without proper authorization.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-13355
|
2024-11-21 12:46 |
2018-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|