|
264651
|
7.2 |
HIGH
Network
|
iodata
|
ts-wrlp_firmware ts-wrla_firmware
|
I-O DATA DEVICE TS-WRLP firmware version 1.01.02 and earlier and TS-WRLA firmware version 1.01.02 and earlier allows an attacker with administrator rights to execute arbitrary OS commands via unspeci…
|
CWE-78
OS Command
|
CVE-2016-7819
|
2024-11-21 11:58 |
2017-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264652
|
7.8 |
HIGH
Local
|
japan_pension_service
|
todokesho_creation_program device_data_encryption_program specification_check_program todokesho_print_program
|
Untrusted search path vulnerability in Installers for Specification check program (social insurance) Ver. 9.00 and earlier, TODOKESHO print program Ver. 5.00 and earlier, Device data encryption progr…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-7818
|
2024-11-21 11:58 |
2017-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264653
|
6.1 |
MEDIUM
Network
|
simple_keitai_chat_project
|
simple_keitai_chat
|
Cross-site scripting vulnerability in Simple keitai chat 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2016-7817
|
2024-11-21 11:58 |
2017-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264654
|
5.9 |
MEDIUM
Network
|
cybozu
|
kintone
|
The Cybozu kintone mobile for Android 1.0.6 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information…
|
CWE-295
Improper Certificate Validation
|
CVE-2016-7816
|
2024-11-21 11:58 |
2017-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264655
|
7.5 |
HIGH
Network
|
iodata
|
ts-wrlp_firmware ts-wrla_firmware
|
I-O DATA DEVICE TS-WRLP firmware version 1.00.01 and earlier and TS-WRLA firmware version 1.00.01 and earlier allow remote attackers to obtain authentication credentials via unspecified vectors.
|
CWE-200
Information Exposure
|
CVE-2016-7814
|
2024-11-21 11:58 |
2017-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264656
|
6.1 |
MEDIUM
Network
|
emon-cms
|
deraemon-cms
|
Cross-site scripting vulnerability in DERAEMON-CMS version 0.8.9 and earlier allows remote attackers to inject arbitrary web script or HTML via the parameters hostname, database and username.
|
CWE-79
Cross-site Scripting
|
CVE-2016-7813
|
2024-11-21 11:58 |
2017-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264657
|
8.8 |
HIGH
Adjacent
|
corega
|
cg-wlr300nx_firmware
|
Corega CG-WLR300NX firmware Ver. 1.20 and earlier allows an attacker on the same network segment to bypass access restriction to perform arbitrary operations via unspecified vectors.
|
CWE-284
Improper Access Control
|
CVE-2016-7811
|
2024-11-21 11:58 |
2017-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264658
|
4.8 |
MEDIUM
Network
|
corega
|
cg-wlr300nx_firmware
|
Cross-site scripting vulnerability in Corega CG-WLR300NX firmware Ver. 1.20 and earlier allows attacker with administrator rights to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2016-7810
|
2024-11-21 11:58 |
2017-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264659
|
8.8 |
HIGH
Network
|
corega
|
cg-wlr300nx_firmware
|
Cross-site request forgery (CSRF) vulnerability in Corega CG-WLR300NX firmware Ver. 1.20 and earlier allows remote attackers to hijack the authentication of logged in user to conduct unintended opera…
|
CWE-352
Origin Validation Error
|
CVE-2016-7809
|
2024-11-21 11:58 |
2017-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264660
|
6.1 |
MEDIUM
Network
|
corega
|
cg-wlbaragm_firmware cg-wlbargnl_firmware
|
Cross-site scripting vulnerability in Corega CG-WLBARGMH and CG-WLBARGNL allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2016-7808
|
2024-11-21 11:58 |
2017-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|