|
264511
|
6.1 |
MEDIUM
Network
|
accellion
|
ftp_server
|
Accellion FTP server prior to version FTA_9_12_220 uses the Accusoft Prizm Content flash component, which contains multiple parameters (customTabCategoryName, customButton1Image) that are vulnerable …
|
CWE-79
Cross-site Scripting
|
CVE-2016-9500
|
2024-11-21 12:01 |
2018-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264512
|
5.3 |
MEDIUM
Network
|
accellion
|
ftp_server
|
Accellion FTP server prior to version FTA_9_12_220 only returns the username in the server response if the username is invalid. An attacker may use this information to determine valid user accounts a…
|
CWE-200
Information Exposure
|
CVE-2016-9499
|
2024-11-21 12:01 |
2018-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264513
|
8.8 |
HIGH
Adjacent
|
hughes
|
hn7740s_firmware dw7000_firmware hn7000s_firmware hn7000sm_firmware
|
Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, is vulnerable to an authentication bypass using an alternate path or channel. By default, port 1953 is accessible…
|
CWE-287
Improper Authentication
|
CVE-2016-9497
|
2024-11-21 12:01 |
2018-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264514
|
6.5 |
MEDIUM
Adjacent
|
hughes
|
hn7740s_firmware dw7000_firmware hn7000s_firmware hn7000sm_firmware
|
Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, lacks authentication. An unauthenticated user may send an HTTP GET request to http://[ip]/com/gatewayreset or htt…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2016-9496
|
2024-11-21 12:01 |
2018-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264515
|
8.8 |
HIGH
Adjacent
|
hughes
|
hn7740s_firmware dw7000_firmware hn7000s_firmware hn7000sm_firmware
|
Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, uses hard coded credentials. Access to the device's default telnet port (23) can be obtained through using one of…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2016-9495
|
2024-11-21 12:01 |
2018-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264516
|
6.5 |
MEDIUM
Adjacent
|
hughes
|
hn7740s_firmware dw7000_firmware hn7000s_firmware hn7000sm_firmware
|
Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, are potentially vulnerable to improper input validation. The device's advanced status web page that is linked to …
|
CWE-20
Improper Input Validation
|
CVE-2016-9494
|
2024-11-21 12:01 |
2018-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264517
|
4.9 |
MEDIUM
Network
|
zohocorp
|
manageengine_applications_manager
|
ManageEngine Applications Manager 12 and 13 before build 13690 allows an authenticated user, who is able to access /register.do page (most likely limited to administrator), to browse the filesystem a…
|
CWE-200
Information Exposure
|
CVE-2016-9491
|
2024-11-21 12:01 |
2018-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264518
|
8.8 |
HIGH
Network
|
zohocorp
|
manageengine_applications_manager
|
In ManageEngine Applications Manager 12 and 13 before build 13200, an authenticated user is able to alter all of their own properties, including own group, i.e. changing their group to one with highe…
|
CWE-255 CWE-264
Credentials Management Permissions, Privileges, and Access Controls
|
CVE-2016-9489
|
2024-11-21 12:01 |
2018-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264519
|
7.8 |
HIGH
Local
|
w3
|
epubcheck
|
EpubCheck 4.0.1 does not properly restrict resolving external entities when parsing XML in EPUB files during validation. An attacker who supplies a specially crafted EPUB file may be able to exploit …
|
CWE-611
XXE
|
CVE-2016-9487
|
2024-11-21 12:01 |
2018-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264520
|
7.5 |
HIGH
Network
|
jqueryform
|
php_formmail_generator
|
The generated PHP form code does not properly validate user input folder directories, allowing a remote unauthenticated attacker to perform a path traversal and access arbitrary files on the server. …
|
CWE-22
Path Traversal
|
CVE-2016-9484
|
2024-11-21 12:01 |
2018-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|