|
249851
|
8.8 |
HIGH
Network
|
asustor
|
data_master
|
OS command injection in group.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root by modifying the "name" POST parameter.
|
CWE-78
OS Command
|
CVE-2018-12317
|
2024-11-21 12:44 |
2018-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249852
|
8.8 |
HIGH
Network
|
asustor
|
data_master
|
OS Command Injection in upload.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands by modifying the filename POST parameter.
|
CWE-78
OS Command
|
CVE-2018-12316
|
2024-11-21 12:44 |
2018-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249853
|
6.5 |
MEDIUM
Network
|
asustor
|
data_master
|
Missing verification of a password in ASUSTOR ADM version 3.1.1 allows attackers to change account passwords without entering the current password.
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2018-12315
|
2024-11-21 12:44 |
2018-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249854
|
7.5 |
HIGH
Network
|
asustor
|
data_master
|
Directory Traversal in downloadwallpaper.cgi in ASUSTOR ADM version 3.1.1 allows attackers to download arbitrary files by manipulating the "file" and "folder" URL parameters.
|
CWE-22
Path Traversal
|
CVE-2018-12314
|
2024-11-21 12:44 |
2018-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249855
|
9.8 |
CRITICAL
Network
|
asustor
|
data_master
|
OS command injection in snmp.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands without authentication via the "rocommunity" URL parameter.
|
CWE-78
OS Command
|
CVE-2018-12313
|
2024-11-21 12:44 |
2018-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249856
|
8.8 |
HIGH
Network
|
asustor
|
data_master
|
OS command injection in user.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root via the "secret_key" URL parameter.
|
CWE-78
OS Command
|
CVE-2018-12312
|
2024-11-21 12:44 |
2018-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249857
|
5.4 |
MEDIUM
Network
|
asustor
|
data_master
|
Cross-site scripting vulnerability in File Explorer in ASUSTOR ADM version 3.1.1 allows attackers to execute arbitrary JavaScript when a file is moved via a malicious filename.
|
CWE-79
Cross-site Scripting
|
CVE-2018-12311
|
2024-11-21 12:44 |
2018-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249858
|
5.4 |
MEDIUM
Network
|
asustor
|
data_master
|
Cross-site scripting in the Login page in ASUSTOR ADM version 3.1.1 allows attackers to execute JavaScript via the System Announcement feature.
|
CWE-79
Cross-site Scripting
|
CVE-2018-12310
|
2024-11-21 12:44 |
2018-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249859
|
7.5 |
HIGH
Network
|
asustor
|
data_master
|
Directory Traversal in upload.cgi in ASUSTOR ADM version 3.1.1 allows attackers to upload files to arbitrary locations by modifying the "path" URL parameter. NOTE: the "filename" POST parameter is c…
|
CWE-22
Path Traversal
|
CVE-2018-12309
|
2024-11-21 12:44 |
2018-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249860
|
6.5 |
MEDIUM
Network
|
asustor
|
data_master
|
Encryption key disclosure in share.cgi in ASUSTOR ADM version 3.1.1 allows attackers to obtain the encryption key via the "encrypt_key" URL parameter.
|
CWE-200
Information Exposure
|
CVE-2018-12308
|
2024-11-21 12:44 |
2018-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|