Show filters
173 Total Results
Displaying 111-120 of 173
Sort by:
Attacker Value
Unknown

CVE-2015-3612

Disclosure Date: February 04, 2020 (last updated February 21, 2025)
A Cross-site Scripting (XSS) vulnerability exists in FortiManager 5.2.1 and earlier and 5.0.10 and earlier via an unspecified parameter in the FortiWeb auto update service page.
Attacker Value
Unknown

CVE-2015-3611

Disclosure Date: February 04, 2020 (last updated February 21, 2025)
A Command Injection vulnerability exists in FortiManager 5.2.1 and earlier and FortiManager 5.0.10 and earlier via unspecified vectors, which could let a malicious user run systems commands when executing a report.
Attacker Value
Unknown

CVE-2015-3613

Disclosure Date: February 04, 2020 (last updated February 21, 2025)
A vulnerability exists in in FortiManager 5.2.1 and earlier and 5.0.10 and earlier in the WebUI FTP backup page
Attacker Value
Unknown

CVE-2019-14835

Disclosure Date: September 17, 2019 (last updated December 16, 2023)
A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descriptors with invalid length to the host when migration is underway, could use this flaw to increase their privileges on the host.
Attacker Value
Unknown

CVE-2019-6695

Disclosure Date: August 23, 2019 (last updated November 27, 2024)
Lack of root file system integrity checking in Fortinet FortiManager VM application images of 6.2.0, 6.0.6 and below may allow an attacker to implant third-party programs by recreating the image through specific methods.
Attacker Value
Unknown

CVE-2019-9506

Disclosure Date: August 14, 2019 (last updated November 27, 2024)
The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext without the victim noticing.
Attacker Value
Unknown

CVE-2019-13375

Disclosure Date: July 06, 2019 (last updated November 08, 2023)
A SQL Injection was discovered in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 in PayAction.class.php with the index.php/Pay/passcodeAuth parameter passcode. The vulnerability does not need any authentication.
0
Attacker Value
Unknown

CVE-2019-13374

Disclosure Date: July 06, 2019 (last updated November 08, 2023)
A cross-site scripting (XSS) vulnerability in resource view in PayAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to inject arbitrary web script or HTML via the index.php/Pay/passcodeAuth passcode parameter.
0
Attacker Value
Unknown

CVE-2019-13372

Disclosure Date: July 06, 2019 (last updated November 08, 2023)
/web/Lib/Action/IndexAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to execute arbitrary PHP code via a cookie because a cookie's username field allows eval injection, and an empty password bypasses authentication.
Attacker Value
Unknown

CVE-2019-13373

Disclosure Date: July 06, 2019 (last updated November 08, 2023)
An issue was discovered in the D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6. Input does not get validated and arbitrary SQL statements can be executed in the database via the /web/Public/Conn.php parameter dbSQL.
0