|
248221
|
9.8 |
CRITICAL
Network
|
saltstack
|
salt
|
In SaltStack Salt before 2016.3.6, compromised salt-minions can impersonate the salt-master.
|
NVD-CWE-noinfo
|
CVE-2017-7893
|
2024-11-21 12:32 |
2018-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248222
|
5.4 |
MEDIUM
Network
|
redhat
|
openshift
|
OpenShift Enterprise version 3.x is vulnerable to a stored XSS via the log viewer for pods. The flaw is due to lack of sanitation of user input, specifically terminal escape characters, and the creat…
|
CWE-79
Cross-site Scripting
|
CVE-2017-7534
|
2024-11-21 12:32 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248223
|
6.1 |
MEDIUM
Network
|
qnap
|
qts
|
Cross-site scripting (XSS) vulnerability in File Station of QNAP QTS 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlier allows remote attackers to inject arbitrary web script or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2017-7632
|
2024-11-21 12:32 |
2018-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248224
|
6.1 |
MEDIUM
Network
|
qnap
|
qts
|
Cross-site scripting (XSS) vulnerability in the share link function of File Station of QNAP 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlier allows remote attackers to inject arbitrary web …
|
CWE-79
Cross-site Scripting
|
CVE-2017-7631
|
2024-11-21 12:32 |
2018-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248225
|
5.3 |
MEDIUM
Network
|
qnap
|
qts
|
QNAP QTS 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlier allows remote attackers to obtain potentially sensitive information (firmware version and running services) via a request to sysinf…
|
CWE-200
Information Exposure
|
CVE-2017-7630
|
2024-11-21 12:32 |
2018-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248226
|
8.8 |
HIGH
Network
|
qnap
|
media_streaming_add-on
|
QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not utilize CSRF protections.
|
CWE-352
Origin Validation Error
|
CVE-2017-7641
|
2024-11-21 12:32 |
2018-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248227
|
9.8 |
CRITICAL
Network
|
qnap
|
media_streaming_add-on
|
QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remote attackers to run arbitrary OS commands against the system with root privileges.
|
CWE-78
OS Command
|
CVE-2017-7640
|
2024-11-21 12:32 |
2018-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248228
|
6.5 |
MEDIUM
Network
|
qnap
|
media_streaming_add-on
|
QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not authenticate requests properly. Successful exploitation could lead to change of the Media Streaming sett…
|
CWE-287
Improper Authentication
|
CVE-2017-7638
|
2024-11-21 12:32 |
2018-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248229
|
6.1 |
MEDIUM
Network
|
qnap
|
media_streaming_add-on
|
Cross-site scripting (XSS) vulnerability in QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remote attackers to inject arbitrary web script or HTML. The i…
|
CWE-79
Cross-site Scripting
|
CVE-2017-7634
|
2024-11-21 12:32 |
2018-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248230
|
7.5 |
HIGH
Network
|
qnap
|
qfinder_pro
|
QNAP Qfinder Pro 6.1.0.0317 and earlier may expose sensitive information contained in NAS devices. If exploited, this may allow attackers to further compromise the device.
|
CWE-200
Information Exposure
|
CVE-2017-7633
|
2024-11-21 12:32 |
2018-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|