Show filters
81 Total Results
Displaying 51-60 of 81
Sort by:
Attacker Value
Unknown

CVE-2019-19017

Disclosure Date: December 02, 2019 (last updated November 27, 2024)
An issue was discovered in TitanHQ WebTitan before 5.18. The appliance has a hard-coded root password set during installation. An attacker could utilize this to gain root privileges on the system.
Attacker Value
Unknown

CVE-2019-19019

Disclosure Date: July 31, 2019 (last updated November 27, 2024)
An issue was discovered in TitanHQ WebTitan before 5.18. It contains a Remote Code Execution issue through which an attacker can execute arbitrary code as root. The issue stems from the hotfix download mechanism, which downloads a shell script via HTTP, and then executes it as root. This is analogous to CVE-2019-6800 but for a different product.
Attacker Value
Unknown

CVE-2018-20841

Disclosure Date: June 11, 2019 (last updated November 27, 2024)
HooToo TripMate Titan HT-TM05 and HT-05 routers with firmware 2.000.022 and 2.000.082 allow remote command execution via shell metacharacters in the mac parameter of a protocol.csp?function=set&fname=security&opt=mac_table request.
0
Attacker Value
Unknown

CVE-2019-6800

Disclosure Date: June 05, 2019 (last updated November 27, 2024)
In TitanHQ SpamTitan through 7.03, a vulnerability exists in the spam rule update function. Updates are downloaded over HTTP, including scripts which are subsequently executed with root permissions. An attacker with a privileged network position is trivially able to inject arbitrary commands.
0
Attacker Value
Unknown

CVE-2019-10009

Disclosure Date: June 03, 2019 (last updated November 27, 2024)
A Directory Traversal issue was discovered in the Web GUI in Titan FTP Server 2019 Build 3505. When an authenticated user attempts to preview an uploaded file (through PreviewHandler.ashx) by using a \..\..\ technique, arbitrary files can be loaded in the server response outside the root directory.
0
Attacker Value
Unknown

CVE-2018-15136

Disclosure Date: January 30, 2019 (last updated November 27, 2024)
TitanHQ SpamTitan before 7.01 has Improper input validation. This allows internal attackers to bypass the anti-spam filter to send malicious emails to an entire organization by modifying the URL requests sent to the application.
0
Attacker Value
Unknown

Nuuo NT-4040 Titan, firmware NT-4040_01.07.0000.0015_1120, uses default credent…

Disclosure Date: July 13, 2018 (last updated November 27, 2024)
Nuuo NT-4040 Titan, firmware NT-4040_01.07.0000.0015_1120, uses non-random default credentials of: admin:admin and localdisplay:111111. A remote network attacker can gain privileged access to a vulnerable device.
0
Attacker Value
Unknown

CVE-2017-18227

Disclosure Date: March 12, 2018 (last updated November 26, 2024)
TitanHQ WebTitan Gateway has incorrect certificate validation for the TLS interception feature.
0
Attacker Value
Unknown

CVE-2014-6444

Disclosure Date: January 08, 2016 (last updated November 25, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in the Titan Framework plugin before 1.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) t parameter to iframe-googlefont-preview.php or the (2) text parameter to iframe-font-preview.php.
0
Attacker Value
Unknown

CVE-2014-2965

Disclosure Date: July 03, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in auth-settings-x.php in SpamTitan before 6.04 allows remote attackers to inject arbitrary web script or HTML via the sortdir parameter.
0