|
249391
|
9.8 |
CRITICAL
Network
|
yeswiki
|
cercopitheque
|
SQL injection vulnerability in the "Bazar" page in Yeswiki Cercopitheque 2018-06-19-1 and earlier allows attackers to execute arbitrary SQL commands via the "id" parameter.
|
CWE-89
SQL Injection
|
CVE-2018-13045
|
2024-11-21 12:46 |
2019-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249392
|
5.3 |
MEDIUM
Network
|
terra-master
|
terramaster_operating_system
|
User enumeration in usertable.php in TerraMaster TOS version 3.1.03 allows attackers to list all system users via the "modgroup" parameter.
|
CWE-20
Improper Input Validation
|
CVE-2018-13361
|
2024-11-21 12:46 |
2018-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249393
|
6.1 |
MEDIUM
Network
|
terra-master
|
terramaster_operating_system
|
Cross-site scripting in Text Editor in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the "filename" URL parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-13360
|
2024-11-21 12:46 |
2018-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249394
|
8.8 |
HIGH
Network
|
terra-master
|
terramaster_operating_system
|
Cross-site scripting in usertable.php in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the "modgroup" parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-13359
|
2024-11-21 12:46 |
2018-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249395
|
8.8 |
HIGH
Network
|
terra-master
|
terramaster_operating_system
|
System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "checkName" parameter.
|
CWE-78
OS Command
|
CVE-2018-13358
|
2024-11-21 12:46 |
2018-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249396
|
5.4 |
MEDIUM
Network
|
terra-master
|
terramaster_operating_system
|
Cross-site scripting in Control Panel in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript when viewing Shared Folders via JavaScript in Shared Folders' names.
|
CWE-79
Cross-site Scripting
|
CVE-2018-13357
|
2024-11-21 12:46 |
2018-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249397
|
8.8 |
HIGH
Network
|
terra-master
|
terramaster_operating_system
|
Incorrect access control on ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to elevate user permissions.
|
CWE-863
Incorrect Authorization
|
CVE-2018-13356
|
2024-11-21 12:46 |
2018-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249398
|
6.5 |
MEDIUM
Network
|
terra-master
|
terramaster_operating_system
|
Incorrect access controls in ajaxdata.php in TerraMaster TOS version 3.1.03 allow attackers to create user groups without proper authorization.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-13355
|
2024-11-21 12:46 |
2018-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249399
|
9.8 |
CRITICAL
Network
|
terra-master
|
terramaster_operating_system
|
System command injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "Event" parameter.
|
CWE-78
OS Command
|
CVE-2018-13354
|
2024-11-21 12:46 |
2018-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249400
|
8.8 |
HIGH
Network
|
terra-master
|
terramaster_operating_system
|
System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute commands via the "checkport" parameter.
|
CWE-78
OS Command
|
CVE-2018-13353
|
2024-11-21 12:46 |
2018-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|