Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown
CVE-2019-12584
Disclosure Date: June 03, 2019 (last updated November 27, 2024)
Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an XSS issue in apcupsd_status.php.
0
Attacker Value
Unknown
CVE-2019-12347
Disclosure Date: May 29, 2019 (last updated November 27, 2024)
In pfSense 2.4.4-p3, a stored XSS vulnerability occurs when attackers inject a payload into the Name or Description field via an acme_accountkeys_edit.php action. The vulnerability occurs due to input validation errors.
0
Attacker Value
Unknown
CVE-2019-11816
Disclosure Date: May 20, 2019 (last updated November 27, 2024)
Incorrect access control in the WebUI in OPNsense before version 19.1.8, and pfsense before 2.4.4-p3 allows remote authenticated users to escalate privileges to administrator via a specially crafted request.
0
Attacker Value
Unknown
CVE-2018-20798
Disclosure Date: March 01, 2019 (last updated November 27, 2024)
The expiretable configuration in pfSense 2.4.4_1 establishes block durations that are incompatible with the block durations implemented by sshguard, which might make it easier for attackers to bypass intended access restrictions.
0
Attacker Value
Unknown
CVE-2018-20799
Disclosure Date: March 01, 2019 (last updated November 27, 2024)
In pfSense 2.4.4_1, blocking of source IP addresses on the basis of failed HTTPS authentication is inconsistent with blocking of source IP addresses on the basis of failed SSH authentication (the behavior does not match the sshguard documentation), which might make it easier for attackers to bypass intended access restrictions.
0
Attacker Value
Unknown
CVE-2018-4019
Disclosure Date: December 03, 2018 (last updated November 27, 2024)
An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request. The attacker can exploit this and gain the ability to execute arbitrary commands on the system. An attacker needs to be able to send authenticated POST requests to the administration web interface. Command injection is possible in the `powerd_normal_mode` parameter.
0
Attacker Value
Unknown
CVE-2018-4020
Disclosure Date: December 03, 2018 (last updated November 27, 2024)
An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request. The attacker can exploit this and gain the ability to execute arbitrary commands on the system. An attacker needs to be able to send authenticated POST requests to the administration web interface. Command injection is possible in the `powerd_ac_mode` POST parameter parameter.
0
Attacker Value
Unknown
CVE-2018-4021
Disclosure Date: December 03, 2018 (last updated November 27, 2024)
An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request. The attacker can exploit this and gain the ability to execute arbitrary commands on the system. An attacker needs to be able to send authenticated POST requests to the administration web interface. Command injection is possible in the `powerd_battery_mode` POST parameter.
0