Show filters
81 Total Results
Displaying 41-50 of 81
Sort by:
Attacker Value
Unknown
CVE-2020-24046
Disclosure Date: September 17, 2020 (last updated February 22, 2025)
A sandbox escape issue was discovered in TitanHQ SpamTitan Gateway 7.07. It limits the admin user to a restricted shell, allowing execution of a small number of tools of the operating system. This restricted shell can be bypassed after changing the properties of the user admin in the operating system file /etc/passwd. This file cannot be accessed though the restricted shell, but it can be modified by abusing the Backup/Import Backup functionality of the web interface. An authenticated attacker would be able to obtain the file /var/tmp/admin.passwd after executing a Backup operation. This file can be manually modified to change the GUID of the user to 0 (root) and change the restricted shell to a normal shell /bin/sh. After the modification is done, the file can be recompressed to a .tar.bz file and imported again via the Import Backup functionality. The properties of the admin user will be overwritten and a root shell will be granted to the user upon the next successful login.
0
Attacker Value
Unknown
CVE-2020-11699
Disclosure Date: September 17, 2020 (last updated February 22, 2025)
An issue was discovered in Titan SpamTitan 7.07. Improper validation of the parameter fname on the page certs-x.php would allow an attacker to execute remote code on the target server. The user has to be authenticated before interacting with this page.
0
Attacker Value
Unknown
CVE-2020-11803
Disclosure Date: September 17, 2020 (last updated February 22, 2025)
An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter jaction when interacting with the page mailqueue.php could lead to PHP code evaluation server-side, because the user-provided input is passed directly to the php eval() function. The user has to be authenticated on the web platform before interacting with the page.
0
Attacker Value
Unknown
CVE-2020-12134
Disclosure Date: April 24, 2020 (last updated February 21, 2025)
Nanometrics Centaur through 4.3.23 and TitanSMA through 4.2.20 mishandle access control for the syslog log.
0
Attacker Value
Unknown
CVE-2019-19018
Disclosure Date: December 02, 2019 (last updated November 27, 2024)
An issue was discovered in TitanHQ WebTitan before 5.18. It exposes a database configuration file under /include/dbconfig.ini in the web administration interface, revealing what database the web application is using.
0
Attacker Value
Unknown
CVE-2019-19020
Disclosure Date: December 02, 2019 (last updated November 27, 2024)
An issue was discovered in TitanHQ WebTitan before 5.18. In the administration web interface it is possible to upload a crafted backup file that enables an attacker to execute arbitrary code by overwriting existing files or adding new PHP files under the web root. This requires the attacker to have access to a valid web interface account.
0
Attacker Value
Unknown
CVE-2019-19014
Disclosure Date: December 02, 2019 (last updated November 27, 2024)
An issue was discovered in TitanHQ WebTitan before 5.18. It has a sudoers file that enables low-privilege users to execute a vast number of commands as root, including mv, chown, and chmod. This can be trivially exploited to gain root privileges by an attacker with access.
0
Attacker Value
Unknown
CVE-2019-19021
Disclosure Date: December 02, 2019 (last updated November 27, 2024)
An issue was discovered in TitanHQ WebTitan before 5.18. It has a hidden support account (with a hard-coded password) in the web administration interface, with administrator privileges. Anybody can log in with this account.
0
Attacker Value
Unknown
CVE-2019-19016
Disclosure Date: December 02, 2019 (last updated November 27, 2024)
An issue was discovered in TitanHQ WebTitan before 5.18. Some functions, such as /history-x.php, of the administration interface are vulnerable to SQL Injection through the results parameter. This could be used by an attacker to extract sensitive information from the appliance database.
0
Attacker Value
Unknown
CVE-2019-19017
Disclosure Date: December 02, 2019 (last updated November 27, 2024)
An issue was discovered in TitanHQ WebTitan before 5.18. The appliance has a hard-coded root password set during installation. An attacker could utilize this to gain root privileges on the system.
0