Show filters
71 Total Results
Displaying 61-70 of 71
Sort by:
Attacker Value
Unknown

CVE-2013-2821

Disclosure Date: December 21, 2013 (last updated October 05, 2023)
NovaTech Orion Substation Automation Platform OrionLX DNP Master 1.27.38 and DNP Slave 1.23.10 and earlier and Orion5/Orion5r DNP Master 1.27.38 and DNP Slave 1.23.10 and earlier allow remote attackers to cause a denial of service (driver crash and process restart) via a crafted DNP3 TCP packet.
0
Attacker Value
Unknown

CVE-2012-4939

Disclosure Date: October 31, 2012 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in IPAMSummaryView.aspx in the IPAM web interface before 3.0-HotFix1 in SolarWinds Orion Network Performance Monitor might allow remote attackers to inject arbitrary web script or HTML via the "Search for an IP address" field.
0
Attacker Value
Unknown

CVE-2012-2577

Disclosure Date: August 12, 2012 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) before 10.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) syslocation, (2) syscontact, or (3) sysName field of an snmpd.conf file.
0
Attacker Value
Unknown

CVE-2012-2602

Disclosure Date: August 12, 2012 (last updated October 04, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) before 10.3.1 allow remote attackers to hijack the authentication of administrators for requests that (1) create user accounts via CreateUserStepContainer actions to Admin/Accounts/Add/OrionAccount.aspx or (2) modify account privileges via a ynAdminRights action to Admin/Accounts/EditAccount.aspx.
0
Attacker Value
Unknown

CVE-2010-4828

Disclosure Date: August 24, 2011 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) 10.1 allow remote attackers to inject arbitrary web script or HTML via the (1) Title parameter to MapView.aspx; NetObject parameter to (2) NodeDetails.aspx and (3) InterfaceDetails.aspx; and the (4) ChartName parameter to CustomChart.aspx.
0
Attacker Value
Unknown

CVE-2009-4493

Disclosure Date: January 13, 2010 (last updated October 04, 2023)
Orion Application Server 2.0.7 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.
0
Attacker Value
Unknown

CVE-2007-1471

Disclosure Date: March 16, 2007 (last updated October 04, 2023)
admin/default.asp in Orion-Blog 2.0 allows remote attackers to bypass authentication controls and gain privileges via a direct URL request for admin/AdminBlogNewsEdit.asp.
0
Attacker Value
Unknown

CVE-2006-0816

Disclosure Date: March 24, 2006 (last updated February 22, 2025)
Orion Application Server before 2.0.7, when running on Windows, allows remote attackers to obtain the source code of JSP files via (1) . (dot) and (2) space characters in the extension of a URL.
0
Attacker Value
Unknown

CVE-2005-2981

Disclosure Date: September 20, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Orion 1.3.8 and 1.4.5 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly quoted in the resulting 404 error page.
0
Attacker Value
Unknown

CVE-2004-1492

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Master of Orion III 1.2.5 and earlier allows remote attackers to cause a denial of service (game exit) via a data packet that contains a large size specifier, which causes a large memory allocation to fail.
0