|
246841
|
4.3 |
MEDIUM
Network
|
asustor
|
as6202t_firmware
|
An insecure direct object reference vulnerability in download.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows the ability to reference the "download_sys_settings" action and then specify files arbitrari…
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2018-11346
|
2024-11-21 12:43 |
2018-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246842
|
8.8 |
HIGH
Network
|
asustor
|
as6202t_firmware
|
An unrestricted file upload vulnerability in upload.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to upload supplied data via the POST parameter filename. This can be used to place attacker …
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-11345
|
2024-11-21 12:43 |
2018-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246843
|
6.5 |
MEDIUM
Network
|
asustor
|
as6202t_firmware
|
A path traversal vulnerability in download.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to arbitrarily specify a file on the system to download via the file1 parameter.
|
CWE-22
Path Traversal
|
CVE-2018-11344
|
2024-11-21 12:43 |
2018-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246844
|
5.4 |
MEDIUM
Network
|
asustor
|
soundsgood
|
A persistent cross site scripting vulnerability in playlistmanger.cgi in the ASUSTOR SoundsGood application allows attackers to store cross site scripting payloads via the 'playlist' POST parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-11343
|
2024-11-21 12:43 |
2018-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246845
|
4.3 |
MEDIUM
Network
|
asustor
|
as6202t_firmware
|
A path traversal vulnerability in fileExplorer.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to arbitrarily specify a path to a file on the system to create folders via the dest_folder param…
|
CWE-22
Path Traversal
|
CVE-2018-11342
|
2024-11-21 12:43 |
2018-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246846
|
7.2 |
HIGH
Network
|
asustor
|
as6202t_firmware
|
Directory traversal in importuser.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to navigate the file system via the filename parameter.
|
CWE-22
Path Traversal
|
CVE-2018-11341
|
2024-11-21 12:43 |
2018-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246847
|
7.2 |
HIGH
Network
|
asustor
|
as6202t_firmware
|
An unrestricted file upload vulnerability in importuser.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to upload supplied data to a specified filename. This can be used to place attacker cont…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-11340
|
2024-11-21 12:43 |
2018-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246848
|
6.1 |
MEDIUM
Network
|
frappe
|
erpnext
|
An XSS issue was discovered in Frappe ERPNext v11.x.x-develop b1036e5 via a comment.
|
CWE-79
Cross-site Scripting
|
CVE-2018-11339
|
2024-11-21 12:43 |
2018-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246849
|
9.8 |
CRITICAL
Network
|
pluck-cms
|
pluck
|
An issue was discovered in Pluck before 4.7.6. Remote PHP code execution is possible because the set of disallowed filetypes for uploads in missing some applicable ones such as .phtml and .htaccess.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-11331
|
2024-11-21 12:43 |
2018-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246850
|
4.8 |
MEDIUM
Network
|
pluck-cms
|
pluck
|
An issue was discovered in Pluck before 4.7.6. There is authenticated stored XSS because the character set for filenames is not properly restricted.
|
CWE-79
Cross-site Scripting
|
CVE-2018-11330
|
2024-11-21 12:43 |
2018-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|