Show filters
173 Total Results
Displaying 121-130 of 173
Sort by:
Attacker Value
Unknown

CVE-2018-13375

Disclosure Date: May 28, 2019 (last updated November 27, 2024)
An Improper Neutralization of Script-Related HTML Tags in Fortinet FortiAnalyzer 5.6.0 and below and FortiManager 5.6.0 and below allows an attacker to send DHCP request containing malicious scripts in the HOSTNAME parameter. The malicious script code is executed while viewing the logs in FortiAnalyzer and FortiManager (with FortiAnalyzer feature enabled).
0
Attacker Value
Unknown

CVE-2018-1360

Disclosure Date: April 25, 2019 (last updated November 27, 2024)
A cleartext transmission of sensitive information vulnerability in Fortinet FortiManager 5.2.0 through 5.2.7, 5.4.0 and 5.4.1 may allow an unauthenticated attacker in a man in the middle position to retrieve the admin password via intercepting REST API JSON responses.
0
Attacker Value
Unknown

CVE-2018-15517

Disclosure Date: January 31, 2019 (last updated November 27, 2024)
The MailConnect feature on D-Link Central WiFiManager CWM-100 1.03 r0098 devices is intended to check a connection to an SMTP server but actually allows outbound TCP to any port on any IP address, leading to SSRF, as demonstrated by an index.php/System/MailConnect/host/127.0.0.1/port/22/secure/ URI.
0
Attacker Value
Unknown

CVE-2018-15515

Disclosure Date: January 31, 2019 (last updated November 27, 2024)
The CaptivelPortal service on D-Link Central WiFiManager CWM-100 1.03 r0098 devices will load a Trojan horse "quserex.dll" from the CaptivelPortal.exe subdirectory under the D-Link directory, which allows unprivileged local users to gain SYSTEM privileges.
0
Attacker Value
Unknown

CVE-2018-15516

Disclosure Date: January 31, 2019 (last updated November 27, 2024)
The FTP service on D-Link Central WiFiManager CWM-100 1.03 r0098 devices allows remote attackers to conduct a PORT command bounce scan via port 8000, resulting in SSRF.
0
Attacker Value
Unknown

CVE-2018-17949

Disclosure Date: December 12, 2018 (last updated November 08, 2023)
Cross site scripting vulnerability in iManager prior to 3.1 SP2.
0
Attacker Value
Unknown

CVE-2018-17442

Disclosure Date: October 08, 2018 (last updated November 27, 2024)
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. An unrestricted file upload vulnerability in the onUploadLogPic endpoint allows remote authenticated users to execute arbitrary PHP code.
0
Attacker Value
Unknown

CVE-2018-17443

Disclosure Date: October 08, 2018 (last updated November 27, 2024)
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'sitename' parameter of the UpdateSite endpoint is vulnerable to stored XSS.
0
Attacker Value
Unknown

CVE-2018-17440

Disclosure Date: October 08, 2018 (last updated November 27, 2024)
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. They expose an FTP server that serves by default on port 9000 and has hardcoded credentials (admin, admin). Taking advantage of this, a remote unauthenticated attacker could execute arbitrary PHP code by uploading any file in the web root directory and then accessing it via a request.
0
Attacker Value
Unknown

CVE-2018-17441

Disclosure Date: October 08, 2018 (last updated November 27, 2024)
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'username' parameter of the addUser endpoint is vulnerable to stored XSS.
0