Show filters
188 Total Results
Displaying 151-160 of 188
Sort by:
Attacker Value
Unknown

CVE-2017-17656

Disclosure Date: February 08, 2018 (last updated November 26, 2024)
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of NVBUBackup JobList method requests. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of the underlying database. Was ZDI-CAN-4292.
0
Attacker Value
Unknown

CVE-2017-15517

Disclosure Date: November 17, 2017 (last updated November 26, 2024)
AltaVault OST Plug-in versions prior to 1.2.2 may allow attackers to obtain sensitive information via unspecified vectors. All users are urged to move to a fixed version and change passwords used by Veritas NetBackup to access the OST shares on the NetApp AltaVault as a precaution.
0
Attacker Value
Unknown

CVE-2017-2809

Disclosure Date: September 14, 2017 (last updated November 26, 2024)
An exploitable vulnerability exists in the yaml loading functionality of ansible-vault before 1.0.5. A specially crafted vault can execute arbitrary python commands resulting in command execution. An attacker can insert python into the vault to trigger this vulnerability.
0
Attacker Value
Unknown

CVE-2017-1000065

Disclosure Date: July 17, 2017 (last updated November 26, 2024)
Multiple Cross-site scripting (XSS) vulnerabilities in rpc.php in OpenMediaVault release 2.1 in Access Rights Management(Users) functionality allows attackers to inject arbitrary web scripts and execute malicious scripts within an authenticated client's browser.
0
Attacker Value
Unknown

CVE-2016-3998

Disclosure Date: July 03, 2017 (last updated November 26, 2024)
NetApp AltaVault 4.1 and earlier allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or cause a denial of service via vectors related to the SMB protocol.
0
Attacker Value
Unknown

CVE-2017-9602

Disclosure Date: June 16, 2017 (last updated November 26, 2024)
KBVault Mysql Free Knowledge Base application package 0.16a comes with a FileExplorer/Explorer.aspx?id=/Uploads file-management component. An unauthenticated user can access the file upload and deletion functionality. Through this functionality, a user can upload an ASPX script to Uploads/Documents/ to run any arbitrary code.
Attacker Value
Unknown

CVE-2015-5711

Disclosure Date: September 29, 2015 (last updated October 05, 2023)
TIBCO Managed File Transfer Internet Server before 7.2.5, Managed File Transfer Command Center before 7.2.5, Slingshot before 1.9.4, and Vault before 2.0.1 allow remote authenticated users to obtain sensitive information via a crafted HTTP request.
0
Attacker Value
Unknown

CVE-2015-5696

Disclosure Date: August 14, 2015 (last updated October 05, 2023)
Dell Netvault Backup before 10.0.5 allows remote attackers to cause a denial of service (crash) via a crafted request.
0
Attacker Value
Unknown

CVE-2004-2777

Disclosure Date: August 04, 2015 (last updated October 05, 2023)
GE Healthcare Centricity Image Vault 3.x has a password of (1) gemnet for the administrator account, (2) webadmin for the webadmin administrator account of the ASACA DVD library, (3) an empty value for the gemsservice account of the Ultrasound Database, and possibly (4) gemnet2002 for the gemnet2002 account of the GEMNet license server, which has unspecified impact and attack vectors. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires a fixed value.
0
Attacker Value
Unknown

CVE-2015-4067

Disclosure Date: May 29, 2015 (last updated October 05, 2023)
Integer overflow in the libnv6 module in Dell NetVault Backup before 10.0.5 allows remote attackers to execute arbitrary code via crafted template string specifiers in a serialized object, which triggers a heap-based buffer overflow.
0