Show filters
194 Total Results
Displaying 101-110 of 194
Sort by:
Attacker Value
Unknown
CVE-2016-10861
Disclosure Date: August 07, 2019 (last updated November 27, 2024)
Neet AirStream NAS1.1 devices allow CSRF attacks that cause the settings binary to change the AP name and password.
0
Attacker Value
Unknown
CVE-2017-18378
Disclosure Date: June 11, 2019 (last updated November 27, 2024)
In NETGEAR ReadyNAS Surveillance before 1.4.3-17 x86 and before 1.1.4-7 ARM, $_GET['uploaddir'] is not escaped and is passed to system() through $tmp_upload_dir, leading to upgrade_handle.php?cmd=writeuploaddir remote command execution.
0
Attacker Value
Unknown
CVE-2018-12300
Disclosure Date: May 13, 2019 (last updated November 27, 2024)
Arbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclose information in the Referer header via the 'state' URL parameter.
0
Attacker Value
Unknown
CVE-2018-12304
Disclosure Date: May 13, 2019 (last updated November 27, 2024)
Cross-site scripting in Application Manager in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via multiple application metadata fields: Short Description, Publisher Name, Publisher Contact, or Website URL.
0
Attacker Value
Unknown
CVE-2018-12298
Disclosure Date: May 13, 2019 (last updated November 27, 2024)
Directory Traversal in filebrowser in Seagate NAS OS 4.3.15.1 allows attackers to read files within the application's container via a URL path.
0
Attacker Value
Unknown
CVE-2018-12296
Disclosure Date: May 13, 2019 (last updated November 27, 2024)
Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attackers to obtain information about the NAS without authentication via empty POST requests.
0
Attacker Value
Unknown
CVE-2018-12302
Disclosure Date: May 13, 2019 (last updated November 27, 2024)
Missing HTTPOnly flag on session cookies in the Seagate NAS OS version 4.3.15.1 web application allows attackers to steal session tokens via cross-site scripting.
0
Attacker Value
Unknown
CVE-2018-12299
Disclosure Date: May 13, 2019 (last updated November 27, 2024)
Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via uploaded file names.
0
Attacker Value
Unknown
CVE-2018-12303
Disclosure Date: May 13, 2019 (last updated November 27, 2024)
Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via directory names.
0
Attacker Value
Unknown
CVE-2018-12301
Disclosure Date: May 13, 2019 (last updated November 27, 2024)
Unvalidated URL in Download Manager in Seagate NAS OS version 4.3.15.1 allows attackers to access the loopback interface via a Download URL of 127.0.0.1 or localhost.
0