Show filters
103 Total Results
Displaying 41-50 of 103
Sort by:
Attacker Value
Unknown
CVE-2018-15697
Disclosure Date: August 27, 2018 (last updated November 27, 2024)
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to read any file on a share by providing the full path. For example, /home/admin/.ash_history.
0
Attacker Value
Unknown
CVE-2018-15696
Disclosure Date: August 27, 2018 (last updated November 27, 2024)
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to enumerate all user accounts via user.cgi.
0
Attacker Value
Unknown
CVE-2018-15698
Disclosure Date: August 27, 2018 (last updated November 27, 2024)
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to read any file on the file system when providing the full path to loginimage.cgi.
0
Attacker Value
Unknown
CVE-2018-15694
Disclosure Date: August 27, 2018 (last updated November 27, 2024)
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to upload files to arbitrary locations due to a path traversal vulnerability. This could lead to code execution if the "Web Server" feature is enabled.
0
Attacker Value
Unknown
CVE-2018-15699
Disclosure Date: August 27, 2018 (last updated November 27, 2024)
ASUSTOR Data Master 3.1.5 and below makes an HTTP request for a configuration file that is vulnerable to XSS. A man in the middle can take advantage of this by inserting Javascript into the configuration files Version field.
0
Attacker Value
Unknown
CVE-2018-15695
Disclosure Date: August 27, 2018 (last updated November 27, 2024)
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to delete any file on the file system due to a path traversal vulnerability in wallpaper.cgi.
0
Attacker Value
Unknown
CVE-2018-11511
Disclosure Date: August 16, 2018 (last updated November 27, 2024)
The tree list functionality in the photo gallery application in ASUSTOR ADM 3.1.0.RFQ3 has a SQL injection vulnerability that affects the 'album_id' or 'scope' parameter via a photo-gallery/api/album/tree_lists/ URI.
0
Attacker Value
Unknown
CVE-2018-11509
Disclosure Date: August 16, 2018 (last updated November 27, 2024)
ASUSTOR ADM 3.1.0.RFQ3 uses the same default root:admin username and password as it does for the NAS itself for applications that are installed from the online repository. This may allow an attacker to login and upload a webshell.
0
Attacker Value
Unknown
CVE-2018-1258
Disclosure Date: May 11, 2018 (last updated November 26, 2024)
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.
0
Attacker Value
Unknown
CVE-2018-1257
Disclosure Date: May 11, 2018 (last updated November 26, 2024)
Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a regular expression, denial of service attack.
0