Show filters
103 Total Results
Displaying 41-50 of 103
Sort by:
Attacker Value
Unknown

CVE-2018-15697

Disclosure Date: August 27, 2018 (last updated November 27, 2024)
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to read any file on a share by providing the full path. For example, /home/admin/.ash_history.
0
Attacker Value
Unknown

CVE-2018-15696

Disclosure Date: August 27, 2018 (last updated November 27, 2024)
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to enumerate all user accounts via user.cgi.
0
Attacker Value
Unknown

CVE-2018-15698

Disclosure Date: August 27, 2018 (last updated November 27, 2024)
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to read any file on the file system when providing the full path to loginimage.cgi.
0
Attacker Value
Unknown

CVE-2018-15694

Disclosure Date: August 27, 2018 (last updated November 27, 2024)
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to upload files to arbitrary locations due to a path traversal vulnerability. This could lead to code execution if the "Web Server" feature is enabled.
0
Attacker Value
Unknown

CVE-2018-15699

Disclosure Date: August 27, 2018 (last updated November 27, 2024)
ASUSTOR Data Master 3.1.5 and below makes an HTTP request for a configuration file that is vulnerable to XSS. A man in the middle can take advantage of this by inserting Javascript into the configuration files Version field.
0
Attacker Value
Unknown

CVE-2018-15695

Disclosure Date: August 27, 2018 (last updated November 27, 2024)
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to delete any file on the file system due to a path traversal vulnerability in wallpaper.cgi.
0
Attacker Value
Unknown

CVE-2018-11511

Disclosure Date: August 16, 2018 (last updated November 27, 2024)
The tree list functionality in the photo gallery application in ASUSTOR ADM 3.1.0.RFQ3 has a SQL injection vulnerability that affects the 'album_id' or 'scope' parameter via a photo-gallery/api/album/tree_lists/ URI.
0
Attacker Value
Unknown

CVE-2018-11509

Disclosure Date: August 16, 2018 (last updated November 27, 2024)
ASUSTOR ADM 3.1.0.RFQ3 uses the same default root:admin username and password as it does for the NAS itself for applications that are installed from the online repository. This may allow an attacker to login and upload a webshell.
0
Attacker Value
Unknown

CVE-2018-1258

Disclosure Date: May 11, 2018 (last updated November 26, 2024)
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.
Attacker Value
Unknown

CVE-2018-1257

Disclosure Date: May 11, 2018 (last updated November 26, 2024)
Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a regular expression, denial of service attack.