|
247211
|
7.5 |
HIGH
Network
|
drobo
|
5n2_firmware
|
Directory traversal in the Drobo Pix web application on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to upload files to arbitrary locations.
|
CWE-22
Path Traversal
|
CVE-2018-14707
|
2024-11-21 12:49 |
2018-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247212
|
9.8 |
CRITICAL
Network
|
drobo
|
5n2_firmware
|
System command injection in the /DroboPix/api/drobopix/demo endpoint on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to execute system commands via the payload in a POST r…
|
CWE-78
OS Command
|
CVE-2018-14706
|
2024-11-21 12:49 |
2018-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247213
|
6.1 |
MEDIUM
Network
|
drobo
|
5n2_firmware
|
Cross-site scripting in the MySQL API error page in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execute JavaScript via a malformed URL path.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14704
|
2024-11-21 12:49 |
2018-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247214
|
9.8 |
CRITICAL
Network
|
drobo
|
5n2_firmware
|
Incorrect access control in the /mysql/api/droboapp/data endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve the MySQL database root password.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-14703
|
2024-11-21 12:49 |
2018-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247215
|
7.5 |
HIGH
Network
|
drobo
|
5n2_firmware
|
Incorrect access control in the /drobopix/api/drobo.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve sensitive system information.
|
CWE-200
Information Exposure
|
CVE-2018-14702
|
2024-11-21 12:49 |
2018-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247216
|
9.8 |
CRITICAL
Network
|
drobo
|
5n2_firmware
|
System command injection in the /DroboAccess/delete_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to execute system commands via the "username" URL paramet…
|
CWE-78
OS Command
|
CVE-2018-14701
|
2024-11-21 12:49 |
2018-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247217
|
7.5 |
HIGH
Network
|
drobo
|
5n2_firmware
|
Incorrect access control in the /mysql/api/logfile.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve MySQL log files via the "name" URL parameter.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2018-14700
|
2024-11-21 12:49 |
2018-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247218
|
9.8 |
CRITICAL
Network
|
drobo
|
5n2_firmware
|
System command injection in the /DroboAccess/enable_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to execute system commands via the "username" URL paramet…
|
CWE-78
OS Command
|
CVE-2018-14699
|
2024-11-21 12:49 |
2018-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247219
|
6.1 |
MEDIUM
Network
|
drobo
|
5n2_firmware
|
Cross-site scripting in the /DroboAccess/delete_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execute JavaScript via the "username" URL parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14698
|
2024-11-21 12:49 |
2018-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247220
|
6.1 |
MEDIUM
Network
|
drobo
|
5n2_firmware
|
Cross-site scripting in the /DroboAccess/enable_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execute JavaScript via the username URL parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14697
|
2024-11-21 12:49 |
2018-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|