Show filters
248 Total Results
Displaying 151-160 of 248
Sort by:
Attacker Value
Unknown

CVE-2017-10936

Disclosure Date: July 25, 2018 (last updated November 27, 2024)
SQL injection vulnerability in all versions prior to V4.01.01 of the ZTE ZXCDN-SNS product allows remote attackers to execute arbitrary SQL commands via the aoData parameter, resulting in the disclosure of database information.
0
Attacker Value
Unknown

CVE-2018-1999021

Disclosure Date: July 23, 2018 (last updated November 27, 2024)
Gleezcms Gleez Cms version 1.3.0 contains a Cross Site Scripting (XSS) vulnerability in Profile page that can result in Inject arbitrary web script or HTML via the profile page editor. This attack appear to be exploitable via The victim must navigate to the attacker's profile page.
0
Attacker Value
Unknown

CVE-2018-13340

Disclosure Date: July 05, 2018 (last updated November 27, 2024)
Gleez CMS 1.2.0 has CSRF, as demonstrated by a /page/add request.
0
Attacker Value
Unknown

CVE-2014-6435

Disclosure Date: January 12, 2018 (last updated November 26, 2024)
cgi-bin/AZ_Retrain.cgi in Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices does not check for authentication, which allows remote attackers to cause a denial of service (WAN connectivity reset) via a direct request.
0
Attacker Value
Unknown

CVE-2014-6436

Disclosure Date: January 12, 2018 (last updated November 26, 2024)
Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices improperly manage sessions, which allows remote attackers to bypass authentication in opportunistic circumstances and execute arbitrary commands with administrator privileges by leveraging an existing web portal login.
0
Attacker Value
Unknown

CVE-2014-6437

Disclosure Date: January 12, 2018 (last updated November 26, 2024)
Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices allow remote attackers to obtain sensitive device configuration information via vectors involving the ROM file.
0
Attacker Value
Unknown

CVE-2017-16953

Disclosure Date: December 01, 2017 (last updated November 26, 2024)
connoppp.cgi on ZTE ZXDSL 831CII devices does not require HTTP Basic Authentication, which allows remote attackers to modify the PPPoE configuration or set up a malicious configuration via a GET request.
0
Attacker Value
Unknown

CVE-2017-10933

Disclosure Date: October 19, 2017 (last updated November 26, 2024)
All versions prior to V2.06.00.00 of ZTE ZXDT22 SF01, an monitoring system of ZTE energy product, are impacted by directory traversal vulnerability that allows remote attackers to read arbitrary files on the system via a full path name after host address.
0
Attacker Value
Unknown

CVE-2017-10932

Disclosure Date: September 28, 2017 (last updated November 26, 2024)
All versions prior to V12.17.20 of the ZTE Microwave NR8000 series products - NR8120, NR8120A, NR8120, NR8150, NR8250, NR8000 TR and NR8950 are the applications of C/S architecture using the Java RMI service in which the servers use the Apache Commons Collections (ACC) library that may result in Java deserialization vulnerabilities. An unauthenticated remote attacker can exploit the vulnerabilities by sending a crafted RMI request to execute arbitrary code on the target host.
0
Attacker Value
Unknown

CVE-2017-10931

Disclosure Date: September 19, 2017 (last updated November 26, 2024)
The ZXR10 1800-2S before v3.00.40 incorrectly restricts the download of the file directory range for WEB users, resulting in the ability to download any files and cause information leaks such as system configuration.
0