Show filters
546 Total Results
Displaying 271-280 of 546
Sort by:
Attacker Value
Unknown

CVE-2020-28187

Disclosure Date: December 24, 2020 (last updated February 22, 2025)
Multiple directory traversal vulnerabilities in TerraMaster TOS <= 4.2.06 allow remote authenticated attackers to read, edit or delete any file within the filesystem via the (1) filename parameter to /tos/index.php?editor/fileGet, Event parameter to /include/ajax/logtable.php, or opt parameter to /include/core/index.php.
Attacker Value
Unknown

CVE-2020-28186

Disclosure Date: December 24, 2020 (last updated February 22, 2025)
Email Injection in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to abuse the forget password functionality and achieve account takeover.
Attacker Value
Unknown

CVE-2020-28185

Disclosure Date: December 24, 2020 (last updated November 28, 2024)
User Enumeration vulnerability in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to identify valid users within the system via the username parameter to wizard/initialise.php.
Attacker Value
Unknown

CVE-2020-28190

Disclosure Date: December 24, 2020 (last updated November 28, 2024)
TerraMaster TOS <= 4.2.06 was found to check for updates (of both system and applications) via an insecure channel (HTTP). Man-in-the-middle attackers are able to intercept these requests and serve a weaponized/infected version of applications or updates.
Attacker Value
Unknown

CVE-2020-28184

Disclosure Date: December 24, 2020 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in TerraMaster TOS <= 4.2.06 allows remote authenticated users to inject arbitrary web script or HTML via the mod parameter to /module/index.php.
Attacker Value
Unknown

CVE-2020-5674

Disclosure Date: November 24, 2020 (last updated February 22, 2025)
Untrusted search path vulnerability in the installers of multiple SEIKO EPSON products allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Attacker Value
Unknown

CVE-2020-27678

Disclosure Date: October 26, 2020 (last updated February 22, 2025)
An issue was discovered in illumos before 2020-10-22, as used in OmniOS before r151030by, r151032ay, and r151034y and SmartOS before 20201022. There is a buffer overflow in parse_user_name in lib/libpam/pam_framework.c.
Attacker Value
Unknown

CVE-2020-24420

Disclosure Date: October 20, 2020 (last updated February 22, 2025)
Adobe Photoshop for Windows version 21.2.1 (and earlier) is affected by an uncontrolled search path element vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Attacker Value
Unknown

CVE-2020-13404

Disclosure Date: August 05, 2020 (last updated February 21, 2025)
The ATOS/Sips (aka Atos-Magento) community module 3.0.0 to 3.0.5 for Magento allows command injection.
Attacker Value
Unknown

CVE-2020-15609

Disclosure Date: July 28, 2020 (last updated February 21, 2025)
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_dashboard.php. When parsing the service_stop parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-9726.