Show filters
21 Total Results
Displaying 11-20 of 21
Sort by:
Attacker Value
Unknown
CVE-2024-9463
Disclosure Date: October 09, 2024 (last updated October 16, 2024)
An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.
0
Attacker Value
Unknown
CVE-2020-1977
Disclosure Date: February 12, 2020 (last updated February 21, 2025)
Insufficient Cross-Site Request Forgery (XSRF) protection on Expedition Migration Tool allows remote unauthenticated attackers to hijack the authentication of administrators and to perform actions on the Expedition Migration Tool. This issue affects Expedition Migration Tool 1.1.51 and earlier versions.
0
Attacker Value
Unknown
CVE-2019-1567
Disclosure Date: October 29, 2019 (last updated December 06, 2023)
The Expedition Migration tool 1.1.6 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the User Mapping Settings.
0
Attacker Value
Unknown
CVE-2019-1574
Disclosure Date: April 12, 2019 (last updated December 06, 2023)
Cross-site scripting (XSS) vulnerability in Palo Alto Networks Expedition Migration tool 1.1.12 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the Devices View.
0
Attacker Value
Unknown
CVE-2019-1574
Disclosure Date: April 12, 2019 (last updated December 06, 2023)
Cross-site scripting (XSS) vulnerability in Palo Alto Networks Expedition Migration tool 1.1.12 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the Devices View.
0
Attacker Value
Unknown
CVE-2019-1567
Disclosure Date: April 09, 2019 (last updated December 06, 2023)
The Expedition Migration tool 1.1.6 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the User Mapping Settings.
0
Attacker Value
Unknown
CVE-2019-1571
Disclosure Date: March 26, 2019 (last updated November 27, 2024)
The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the RADIUS server settings.
0
Attacker Value
Unknown
CVE-2019-1570
Disclosure Date: March 26, 2019 (last updated November 27, 2024)
The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the LDAP server settings.
0
Attacker Value
Unknown
CVE-2019-1569
Disclosure Date: March 26, 2019 (last updated November 27, 2024)
The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the User Mapping Settings for account name of admin user.
0
Attacker Value
Unknown
CVE-2018-10143
Disclosure Date: December 12, 2018 (last updated November 27, 2024)
The Palo Alto Networks Expedition Migration tool 1.0.107 and earlier may allow an unauthenticated attacker with remote access to run system level commands on the device hosting this service/application.
0