Show filters
57 Total Results
Displaying 51-57 of 57
Sort by:
Attacker Value
Unknown

CVE-2020-3934

Disclosure Date: February 11, 2020 (last updated November 27, 2024)
TAIWAN SECOM CO., LTD., a Door Access Control and Personnel Attendance Management system, contains a vulnerability of Pre-auth SQL Injection, allowing attackers to inject a specific SQL command.
Attacker Value
Unknown

Openfind MAIL2000 Webmail Pre-Auth Open Redirect

Disclosure Date: November 20, 2019 (last updated November 27, 2024)
An Open Redirect vulnerability for all browsers in MAIL2000 through version 6.0 and 7.0, which will redirect to a malicious site without authentication. This vulnerability affects many mail system of governments, organizations, companies and universities.
Attacker Value
Unknown

Openfind MAIL2000 Webmail Pre-Auth Cross-Site Scripting

Disclosure Date: November 20, 2019 (last updated November 27, 2024)
The "/cgi-bin/go" page in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code via ACTION parameter without authentication. The code can executed for any user accessing the page. This vulnerability affects many mail system of governments, organizations, companies and universities.
Attacker Value
Unknown

CVE-2015-9136

Disclosure Date: April 18, 2018 (last updated November 26, 2024)
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9640, MDM9650, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 600, SD 625, SD 650/52, SD 808, SD 810, SD 820, SD 835, and SDX20, in pre-auth request, Host driver uses FT IEs sent by the supplicant. A buffer overflow may occur if FT IEs sent by the supplicant are larger than the expected value.
0
Attacker Value
Unknown

CVE-2014-3206

Disclosure Date: February 23, 2018 (last updated November 26, 2024)
Seagate BlackArmor NAS allows remote attackers to execute arbitrary code via the session parameter to localhost/backupmgt/localJob.php or the auth_name parameter to localhost/backupmgmt/pre_connect_check.php.
0
Attacker Value
Unknown

CVE-2017-8897

Disclosure Date: May 11, 2017 (last updated November 26, 2024)
Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has pre-auth reflected XSS in the IPS UTF8 Converter v1.1.18: admin/convertutf8/index.php?controller= is the attack vector. This UTF8 Converter vulnerability can easily be used to make a malicious announcement affecting any Invision Power Board user who views the announcement.
0
Attacker Value
Unknown

CVE-2013-2030

Disclosure Date: December 27, 2013 (last updated October 05, 2023)
keystone/middleware/auth_token.py in OpenStack Nova Folsom, Grizzly, and Havana uses an insecure temporary directory for storing signing certificates, which allows local users to spoof servers by pre-creating this directory, which is reused by Nova, as demonstrated using /tmp/keystone-signing-nova on Fedora.
0