Show filters
248 Total Results
Displaying 151-160 of 248
Sort by:
Attacker Value
Unknown
CVE-2017-10936
Disclosure Date: July 25, 2018 (last updated November 27, 2024)
SQL injection vulnerability in all versions prior to V4.01.01 of the ZTE ZXCDN-SNS product allows remote attackers to execute arbitrary SQL commands via the aoData parameter, resulting in the disclosure of database information.
0
Attacker Value
Unknown
CVE-2018-1999021
Disclosure Date: July 23, 2018 (last updated November 27, 2024)
Gleezcms Gleez Cms version 1.3.0 contains a Cross Site Scripting (XSS) vulnerability in Profile page that can result in Inject arbitrary web script or HTML via the profile page editor. This attack appear to be exploitable via The victim must navigate to the attacker's profile page.
0
Attacker Value
Unknown
CVE-2018-13340
Disclosure Date: July 05, 2018 (last updated November 27, 2024)
Gleez CMS 1.2.0 has CSRF, as demonstrated by a /page/add request.
0
Attacker Value
Unknown
CVE-2014-6435
Disclosure Date: January 12, 2018 (last updated November 26, 2024)
cgi-bin/AZ_Retrain.cgi in Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices does not check for authentication, which allows remote attackers to cause a denial of service (WAN connectivity reset) via a direct request.
0
Attacker Value
Unknown
CVE-2014-6436
Disclosure Date: January 12, 2018 (last updated November 26, 2024)
Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices improperly manage sessions, which allows remote attackers to bypass authentication in opportunistic circumstances and execute arbitrary commands with administrator privileges by leveraging an existing web portal login.
0
Attacker Value
Unknown
CVE-2014-6437
Disclosure Date: January 12, 2018 (last updated November 26, 2024)
Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices allow remote attackers to obtain sensitive device configuration information via vectors involving the ROM file.
0
Attacker Value
Unknown
CVE-2017-16953
Disclosure Date: December 01, 2017 (last updated November 26, 2024)
connoppp.cgi on ZTE ZXDSL 831CII devices does not require HTTP Basic Authentication, which allows remote attackers to modify the PPPoE configuration or set up a malicious configuration via a GET request.
0
Attacker Value
Unknown
CVE-2017-10933
Disclosure Date: October 19, 2017 (last updated November 26, 2024)
All versions prior to V2.06.00.00 of ZTE ZXDT22 SF01, an monitoring system of ZTE energy product, are impacted by directory traversal vulnerability that allows remote attackers to read arbitrary files on the system via a full path name after host address.
0
Attacker Value
Unknown
CVE-2017-10932
Disclosure Date: September 28, 2017 (last updated November 26, 2024)
All versions prior to V12.17.20 of the ZTE Microwave NR8000 series products - NR8120, NR8120A, NR8120, NR8150, NR8250, NR8000 TR and NR8950 are the applications of C/S architecture using the Java RMI service in which the servers use the Apache Commons Collections (ACC) library that may result in Java deserialization vulnerabilities. An unauthenticated remote attacker can exploit the vulnerabilities by sending a crafted RMI request to execute arbitrary code on the target host.
0
Attacker Value
Unknown
CVE-2017-10931
Disclosure Date: September 19, 2017 (last updated November 26, 2024)
The ZXR10 1800-2S before v3.00.40 incorrectly restricts the download of the file directory range for WEB users, resulting in the ability to download any files and cause information leaks such as system configuration.
0