|
246351
|
9.8 |
CRITICAL
Network
|
western_digital
|
my_cloud_wdbctl0020hwt_firmware my_cloud_pr4100 my_cloud_pr2100_firmware my_cloud_mirror_gen_2_firmware my_cloud_mirror_firmware my_cloud_ex4100 my_cloud_ex4_firmware my_cloud_ex…
|
It was discovered that the Western Digital My Cloud device before 2.30.196 is affected by an authentication bypass vulnerability. An unauthenticated attacker can exploit this vulnerability to authent…
|
CWE-287
Improper Authentication
|
CVE-2018-17153
|
2024-11-21 12:53 |
2018-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246352
|
6.1 |
MEDIUM
Network
|
oracle
|
webcenter_interaction
|
The login function of Oracle WebCenter Interaction Portal 10.3.3 is vulnerable to reflected cross-site scripting (XSS). The content of the in_hi_redirect parameter, when prefixed with the https:// sc…
|
CWE-79
Cross-site Scripting
|
CVE-2018-16955
|
2024-11-21 12:53 |
2018-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246353
|
6.1 |
MEDIUM
Network
|
oracle
|
webcenter_interaction
|
An issue was discovered in Oracle WebCenter Interaction Portal 10.3.3. The login function of the portal is vulnerable to insecure redirection (also called an open redirect). The in_hi_redirect parame…
|
CWE-601
Open Redirect
|
CVE-2018-16954
|
2024-11-21 12:53 |
2018-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246354
|
6.1 |
MEDIUM
Network
|
oracle
|
webcenter_interaction
|
The AjaxView::DisplayResponse() function of the portalpages.dll assembly in Oracle WebCenter Interaction Portal 10.3.3 is vulnerable to reflected cross-site scripting (XSS). User input from the name …
|
CWE-79
Cross-site Scripting
|
CVE-2018-16953
|
2024-11-21 12:53 |
2018-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246355
|
5.3 |
MEDIUM
Network
|
oracle
|
webcenter_interaction
|
An issue was discovered in Oracle WebCenter Interaction Portal 10.3.3. The portal component is delivered with an insecure default User Profile community configuration that allows anonymous users to r…
|
CWE-200
Information Exposure
|
CVE-2018-16959
|
2024-11-21 12:53 |
2018-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246356
|
5.4 |
MEDIUM
Network
|
oracle
|
webcenter_interaction
|
An issue was discovered in Oracle WebCenter Interaction Portal 10.3.3. The ASP.NET_SessionID primary session cookie, when Internet Information Services (IIS) with ASP.NET is used, is not protected wi…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-16958
|
2024-11-21 12:53 |
2018-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246357
|
9.8 |
CRITICAL
Network
|
oracle
|
webcenter_interaction
|
The Oracle WebCenter Interaction 10.3.3 search service queryd.exe binary is compiled with the i1g2s3c4 hardcoded password. Authentication to the Oracle WCI search service uses this hardcoded password…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2018-16957
|
2024-11-21 12:53 |
2018-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246358
|
6.5 |
MEDIUM
Network
|
oracle
|
webcenter_interaction
|
The AjaxControl component of Oracle WebCenter Interaction Portal 10.3.3 does not validate the names of pages when processing page rename requests. Pages can be renamed to include characters unsupport…
|
CWE-20
Improper Input Validation
|
CVE-2018-16956
|
2024-11-21 12:53 |
2018-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246359
|
8.8 |
HIGH
Network
|
oracle
|
webcenter_interaction
|
The Oracle WebCenter Interaction Portal 10.3.3 does not implement protection against Cross-site Request Forgery in its design. The impact is sensitive actions in the portal (such as changing a portal…
|
CWE-352
Origin Validation Error
|
CVE-2018-16952
|
2024-11-21 12:53 |
2018-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246360
|
7.5 |
HIGH
Network
|
golang fedoraproject
|
net fedora
|
The html package (aka x/net/html) through 2018-09-17 in Go mishandles <template><tBody><isindex/action=0>, leading to a "panic: runtime error" in inBodyIM in parse.go during an html.Parse call.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-17143
|
2024-11-21 12:53 |
2018-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|