|
247121
|
8.8 |
HIGH
Network
|
asus
|
dsl-n12e_c1_firmware
|
Main_Analysis_Content.asp in ASUS DSL-N12E_C1 1.1.2.3_345 is prone to Authenticated Remote Command Execution, which allows a remote attacker to execute arbitrary OS commands via service parameters, s…
|
CWE-78
OS Command
|
CVE-2018-15887
|
2024-11-21 12:51 |
2018-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247122
|
7.5 |
HIGH
Network
|
visiology
|
flipbox
|
Visiology Flipbox Software Suite before 2.7.0 allows directory traversal via %5c%2e%2e%2f because it does not sanitize filename parameters.
|
CWE-22
Path Traversal
|
CVE-2018-15810
|
2024-11-21 12:51 |
2018-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247123
|
6.1 |
MEDIUM
Network
|
asustor
|
data_master
|
ASUSTOR Data Master 3.1.5 and below makes an HTTP request for a configuration file that is vulnerable to XSS. A man in the middle can take advantage of this by inserting Javascript into the configura…
|
CWE-79
Cross-site Scripting
|
CVE-2018-15699
|
2024-11-21 12:51 |
2018-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247124
|
6.5 |
MEDIUM
Network
|
asustor
|
data_master
|
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to read any file on the file system when providing the full path to loginimage.cgi.
|
CWE-200
Information Exposure
|
CVE-2018-15698
|
2024-11-21 12:51 |
2018-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247125
|
6.5 |
MEDIUM
Network
|
asustor
|
data_master
|
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to read any file on a share by providing the full path. For example, /home/admin/.ash_history.
|
CWE-200
Information Exposure
|
CVE-2018-15697
|
2024-11-21 12:51 |
2018-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247126
|
4.3 |
MEDIUM
Network
|
asustor
|
data_master
|
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to enumerate all user accounts via user.cgi.
|
CWE-200
Information Exposure
|
CVE-2018-15696
|
2024-11-21 12:51 |
2018-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247127
|
6.5 |
MEDIUM
Network
|
asustor
|
data_master
|
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to delete any file on the file system due to a path traversal vulnerability in wallpaper.cgi.
|
CWE-22
Path Traversal
|
CVE-2018-15695
|
2024-11-21 12:51 |
2018-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247128
|
7.5 |
HIGH
Network
|
asustor
|
data_master
|
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to upload files to arbitrary locations due to a path traversal vulnerability. This could lead to code executio…
|
CWE-22
Path Traversal
|
CVE-2018-15694
|
2024-11-21 12:51 |
2018-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247129
|
6.1 |
MEDIUM
Network
|
1234n
|
minicms
|
An issue was discovered in MiniCMS 1.10. There is a post.php?date= XSS vulnerability.
|
CWE-79
Cross-site Scripting
|
CVE-2018-15899
|
2024-11-21 12:51 |
2018-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247130
|
7.5 |
HIGH
Network
|
icmsdev
|
icms
|
An SSRF vulnerability was discovered in idreamsoft iCMS 7.0.11 because the remote function in app/spider/spider_tools.class.php does not block DNS hostnames associated with private and reserved IP ad…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2018-15895
|
2024-11-21 12:51 |
2018-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|