Show filters
55 Total Results
Displaying 11-20 of 55
Sort by:
Attacker Value
Unknown
CVE-2023-34994
Disclosure Date: September 05, 2023 (last updated February 25, 2025)
An improper resource allocation vulnerability exists in the OAS Engine configuration management functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to creation of an arbitrary directory. An attacker can send a sequence of requests to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2023-34353
Disclosure Date: September 05, 2023 (last updated February 25, 2025)
An authentication bypass vulnerability exists in the OAS Engine authentication functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted network sniffing can lead to decryption of sensitive information. An attacker can sniff network traffic to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2023-34317
Disclosure Date: September 05, 2023 (last updated February 25, 2025)
An improper input validation vulnerability exists in the OAS Engine User Creation functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to unexpected data in the configuration. An attacker can send a sequence of requests to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2023-32615
Disclosure Date: September 05, 2023 (last updated February 25, 2025)
A file write vulnerability exists in the OAS Engine configuration functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to arbitrary file creation or overwrite. An attacker can send a sequence of requests to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2023-32271
Disclosure Date: September 05, 2023 (last updated February 25, 2025)
An information disclosure vulnerability exists in the OAS Engine configuration management functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to a disclosure of sensitive information. An attacker can send a sequence of requests to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2023-31242
Disclosure Date: September 05, 2023 (last updated February 25, 2025)
An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072. A specially-crafted series of network requests can lead to arbitrary authentication. An attacker can send a sequence of requests to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2022-47053
Disclosure Date: April 12, 2023 (last updated February 24, 2025)
An arbitrary file upload vulnerability in the Digital Assets Manager module of DNN Corp DotNetNuke v7.0.0 to v9.10.2 allows attackers to execute arbitrary code via a crafted SVG file.
0
Attacker Value
Unknown
CVE-2022-45184
Disclosure Date: November 14, 2022 (last updated February 24, 2025)
The Web Server in Ironman Software PowerShell Universal v3.x and v2.x allows for directory traversal outside of the configuration directory, which allows a remote attacker with administrator privilege to create, delete, update, and display files outside of the configuration directory via a crafted HTTP request to particular endpoints in the web server. Patched Versions are 3.5.3 and 3.4.7.
0
Attacker Value
Unknown
CVE-2022-45183
Disclosure Date: November 14, 2022 (last updated February 24, 2025)
Escalation of privileges in the Web Server in Ironman Software PowerShell Universal 2.x and 3.x allows an attacker with a valid app token to retrieve other app tokens by ID via an HTTP web request. Patched Versions are 3.5.3, 3.4.7, and 2.12.6.
0
Attacker Value
Unknown
CVE-2022-2922
Disclosure Date: September 30, 2022 (last updated February 24, 2025)
Relative Path Traversal in GitHub repository dnnsoftware/dnn.platform prior to 9.11.0.
0