Show filters
39 Total Results
Displaying 31-39 of 39
Sort by:
Attacker Value
Unknown

CVE-2020-26124

Disclosure Date: October 02, 2020 (last updated February 22, 2025)
openmediavault before 4.1.36 and 5.x before 5.5.12 allows authenticated PHP code injection attacks, via the sortfield POST parameter of rpc.php, because json_encode_safe is not used in config/databasebackend.inc. Successful exploitation allows arbitrary command execution on the underlying operating system as root.
Attacker Value
Unknown

CVE-2018-19037

Disclosure Date: May 13, 2019 (last updated November 27, 2024)
On Virgin Media wireless router 3.0 hub devices, the web interface is vulnerable to denial of service. When POST requests are sent and keep the connection open, the router lags and becomes unusable to anyone currently using the web interface.
0
Attacker Value
Unknown

CVE-2018-20390

Disclosure Date: December 23, 2018 (last updated November 27, 2024)
Kaonmedia CG2001-AN22A 1.2.1, CG2001-UDBNA 3.0.8, and CG2001-UN2NA 3.0.8 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.
0
Attacker Value
Unknown

CVE-2017-1000065

Disclosure Date: July 17, 2017 (last updated November 26, 2024)
Multiple Cross-site scripting (XSS) vulnerabilities in rpc.php in OpenMediaVault release 2.1 in Access Rights Management(Users) functionality allows attackers to inject arbitrary web scripts and execute malicious scripts within an authenticated client's browser.
0
Attacker Value
Unknown

CVE-2012-3577

Disclosure Date: June 17, 2012 (last updated October 04, 2023)
Unrestricted file upload vulnerability in doupload.php in the Nmedia Member Conversation plugin before 1.4 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/uploads/user_uploads.
0
Attacker Value
Unknown

CVE-2008-2450

Disclosure Date: May 27, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the Statistics (aka ke_stats) extension 0.1.2 and earlier for TYPO3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2008-2452

Disclosure Date: May 27, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Questionaire (aka pbsurvey) extension 1.2.0 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2008-2451

Disclosure Date: May 27, 2008 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in the Statistics (aka ke_stats) extension 0.1.2 and earlier for TYPO3 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown

CVE-2007-0088

Disclosure Date: January 05, 2007 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in openmedia allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) src parameter to page.php or the (2) format parameter to search_form.php.
0