Show filters
55 Total Results
Displaying 11-20 of 55
Sort by:
Attacker Value
Unknown

CVE-2023-34994

Disclosure Date: September 05, 2023 (last updated February 25, 2025)
An improper resource allocation vulnerability exists in the OAS Engine configuration management functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to creation of an arbitrary directory. An attacker can send a sequence of requests to trigger this vulnerability.
Attacker Value
Unknown

CVE-2023-34353

Disclosure Date: September 05, 2023 (last updated February 25, 2025)
An authentication bypass vulnerability exists in the OAS Engine authentication functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted network sniffing can lead to decryption of sensitive information. An attacker can sniff network traffic to trigger this vulnerability.
Attacker Value
Unknown

CVE-2023-34317

Disclosure Date: September 05, 2023 (last updated February 25, 2025)
An improper input validation vulnerability exists in the OAS Engine User Creation functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to unexpected data in the configuration. An attacker can send a sequence of requests to trigger this vulnerability.
Attacker Value
Unknown

CVE-2023-32615

Disclosure Date: September 05, 2023 (last updated February 25, 2025)
A file write vulnerability exists in the OAS Engine configuration functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to arbitrary file creation or overwrite. An attacker can send a sequence of requests to trigger this vulnerability.
Attacker Value
Unknown

CVE-2023-32271

Disclosure Date: September 05, 2023 (last updated February 25, 2025)
An information disclosure vulnerability exists in the OAS Engine configuration management functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to a disclosure of sensitive information. An attacker can send a sequence of requests to trigger this vulnerability.
Attacker Value
Unknown

CVE-2023-31242

Disclosure Date: September 05, 2023 (last updated February 25, 2025)
An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072. A specially-crafted series of network requests can lead to arbitrary authentication. An attacker can send a sequence of requests to trigger this vulnerability.
Attacker Value
Unknown

CVE-2022-47053

Disclosure Date: April 12, 2023 (last updated February 24, 2025)
An arbitrary file upload vulnerability in the Digital Assets Manager module of DNN Corp DotNetNuke v7.0.0 to v9.10.2 allows attackers to execute arbitrary code via a crafted SVG file.
Attacker Value
Unknown

CVE-2022-45184

Disclosure Date: November 14, 2022 (last updated February 24, 2025)
The Web Server in Ironman Software PowerShell Universal v3.x and v2.x allows for directory traversal outside of the configuration directory, which allows a remote attacker with administrator privilege to create, delete, update, and display files outside of the configuration directory via a crafted HTTP request to particular endpoints in the web server. Patched Versions are 3.5.3 and 3.4.7.
Attacker Value
Unknown

CVE-2022-45183

Disclosure Date: November 14, 2022 (last updated February 24, 2025)
Escalation of privileges in the Web Server in Ironman Software PowerShell Universal 2.x and 3.x allows an attacker with a valid app token to retrieve other app tokens by ID via an HTTP web request. Patched Versions are 3.5.3, 3.4.7, and 2.12.6.
Attacker Value
Unknown

CVE-2022-2922

Disclosure Date: September 30, 2022 (last updated February 24, 2025)
Relative Path Traversal in GitHub repository dnnsoftware/dnn.platform prior to 9.11.0.