Show filters
43 Total Results
Displaying 11-20 of 43
Sort by:
Attacker Value
Unknown

CVE-2019-11688

Disclosure Date: March 18, 2020 (last updated February 21, 2025)
An issue was discovered in ASUSTOR exFAT Driver through 1.0.0.r20. When conducting license validation, exfat.cgi and exfatctl accept any certificate for asustornasapi.asustor.com. In other words, there is Missing SSL Certificate Validation.
Attacker Value
Unknown

CVE-2019-11689

Disclosure Date: March 18, 2020 (last updated February 21, 2025)
An issue was discovered in ASUSTOR exFAT Driver through 1.0.0.r20. When conducting license validation, exfat.cgi and exfatctl fail to properly validate server responses and pass unsanitized text to the system shell, resulting in code execution as root.
Attacker Value
Unknown

CVE-2018-12319

Disclosure Date: December 04, 2018 (last updated November 27, 2024)
Denial-of-service in the login page of ASUSTOR ADM 3.1.1 allows attackers to prevent users from signing in by placing malformed text in the title.
0
Attacker Value
Unknown

CVE-2018-12307

Disclosure Date: December 04, 2018 (last updated November 27, 2024)
OS command injection in user.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root via the "name" POST parameter.
0
Attacker Value
Unknown

CVE-2018-12315

Disclosure Date: December 04, 2018 (last updated November 27, 2024)
Missing verification of a password in ASUSTOR ADM version 3.1.1 allows attackers to change account passwords without entering the current password.
0
Attacker Value
Unknown

CVE-2018-12313

Disclosure Date: December 04, 2018 (last updated November 27, 2024)
OS command injection in snmp.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands without authentication via the "rocommunity" URL parameter.
0
Attacker Value
Unknown

CVE-2018-12318

Disclosure Date: December 04, 2018 (last updated November 27, 2024)
Information disclosure in the SNMP settings page in ASUSTOR ADM version 3.1.1 allows attackers to obtain the SNMP password in cleartext.
0
Attacker Value
Unknown

CVE-2018-12309

Disclosure Date: December 04, 2018 (last updated November 27, 2024)
Directory Traversal in upload.cgi in ASUSTOR ADM version 3.1.1 allows attackers to upload files to arbitrary locations by modifying the "path" URL parameter. NOTE: the "filename" POST parameter is covered by CVE-2018-11345.
0
Attacker Value
Unknown

CVE-2018-12311

Disclosure Date: December 04, 2018 (last updated November 27, 2024)
Cross-site scripting vulnerability in File Explorer in ASUSTOR ADM version 3.1.1 allows attackers to execute arbitrary JavaScript when a file is moved via a malicious filename.
0
Attacker Value
Unknown

CVE-2018-12317

Disclosure Date: December 04, 2018 (last updated November 27, 2024)
OS command injection in group.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root by modifying the "name" POST parameter.
0