Show filters
69 Total Results
Displaying 21-30 of 69
Sort by:
Attacker Value
Unknown
CVE-2023-48250
Disclosure Date: January 10, 2024 (last updated January 18, 2024)
The vulnerability allows a remote attacker to authenticate to the web application with high privileges through multiple hidden hard-coded accounts.
0
Attacker Value
Unknown
CVE-2023-48249
Disclosure Date: January 10, 2024 (last updated January 17, 2024)
The vulnerability allows an authenticated remote attacker to list arbitrary folders in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request.
By abusing this vulnerability, it is possible to steal session cookies of other active users.
0
Attacker Value
Unknown
CVE-2023-48248
Disclosure Date: January 10, 2024 (last updated January 18, 2024)
The vulnerability allows an authenticated remote attacker to upload a malicious file to the SD card containing arbitrary client-side script code and obtain its execution inside a victim’s session via a crafted URL, HTTP request, or simply by waiting for the victim to view the poisoned file.
0
Attacker Value
Unknown
CVE-2023-48247
Disclosure Date: January 10, 2024 (last updated January 17, 2024)
The vulnerability allows an unauthenticated remote attacker to read arbitrary files under the context of the application OS user (“root”) via a crafted HTTP request.
0
Attacker Value
Unknown
CVE-2023-48246
Disclosure Date: January 10, 2024 (last updated January 17, 2024)
The vulnerability allows a remote attacker to download arbitrary files in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request.
0
Attacker Value
Unknown
CVE-2023-48245
Disclosure Date: January 10, 2024 (last updated January 17, 2024)
The vulnerability allows an unauthenticated remote attacker to upload arbitrary files under the context of the application OS user (“root”) via a crafted HTTP request.
0
Attacker Value
Unknown
CVE-2023-48244
Disclosure Date: January 10, 2024 (last updated January 17, 2024)
The vulnerability allows a remote attacker to inject and execute arbitrary client-side script code inside a victim’s session via a crafted URL or HTTP request.
0
Attacker Value
Unknown
CVE-2023-48243
Disclosure Date: January 10, 2024 (last updated January 17, 2024)
The vulnerability allows a remote attacker to upload arbitrary files in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request.
By abusing this vulnerability, it is possible to obtain remote code execution (RCE) with root privileges on the device.
0
Attacker Value
Unknown
CVE-2023-48242
Disclosure Date: January 10, 2024 (last updated January 17, 2024)
The vulnerability allows an authenticated remote attacker to download arbitrary files in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request.
0
Attacker Value
Unknown
CVE-2023-43121
Disclosure Date: October 16, 2023 (last updated October 28, 2023)
A Directory Traversal vulnerability discovered in Chalet application in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, before 22.7, and before 31.7.2 allows attackers to read arbitrary files.
0