Show filters
71 Total Results
Displaying 61-70 of 71
Sort by:
Attacker Value
Unknown
CVE-2013-2821
Disclosure Date: December 21, 2013 (last updated October 05, 2023)
NovaTech Orion Substation Automation Platform OrionLX DNP Master 1.27.38 and DNP Slave 1.23.10 and earlier and Orion5/Orion5r DNP Master 1.27.38 and DNP Slave 1.23.10 and earlier allow remote attackers to cause a denial of service (driver crash and process restart) via a crafted DNP3 TCP packet.
0
Attacker Value
Unknown
CVE-2012-4939
Disclosure Date: October 31, 2012 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in IPAMSummaryView.aspx in the IPAM web interface before 3.0-HotFix1 in SolarWinds Orion Network Performance Monitor might allow remote attackers to inject arbitrary web script or HTML via the "Search for an IP address" field.
0
Attacker Value
Unknown
CVE-2012-2577
Disclosure Date: August 12, 2012 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) before 10.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) syslocation, (2) syscontact, or (3) sysName field of an snmpd.conf file.
0
Attacker Value
Unknown
CVE-2012-2602
Disclosure Date: August 12, 2012 (last updated October 04, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) before 10.3.1 allow remote attackers to hijack the authentication of administrators for requests that (1) create user accounts via CreateUserStepContainer actions to Admin/Accounts/Add/OrionAccount.aspx or (2) modify account privileges via a ynAdminRights action to Admin/Accounts/EditAccount.aspx.
0
Attacker Value
Unknown
CVE-2010-4828
Disclosure Date: August 24, 2011 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) 10.1 allow remote attackers to inject arbitrary web script or HTML via the (1) Title parameter to MapView.aspx; NetObject parameter to (2) NodeDetails.aspx and (3) InterfaceDetails.aspx; and the (4) ChartName parameter to CustomChart.aspx.
0
Attacker Value
Unknown
CVE-2009-4493
Disclosure Date: January 13, 2010 (last updated October 04, 2023)
Orion Application Server 2.0.7 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.
0
Attacker Value
Unknown
CVE-2007-1471
Disclosure Date: March 16, 2007 (last updated October 04, 2023)
admin/default.asp in Orion-Blog 2.0 allows remote attackers to bypass authentication controls and gain privileges via a direct URL request for admin/AdminBlogNewsEdit.asp.
0
Attacker Value
Unknown
CVE-2006-0816
Disclosure Date: March 24, 2006 (last updated February 22, 2025)
Orion Application Server before 2.0.7, when running on Windows, allows remote attackers to obtain the source code of JSP files via (1) . (dot) and (2) space characters in the extension of a URL.
0
Attacker Value
Unknown
CVE-2005-2981
Disclosure Date: September 20, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Orion 1.3.8 and 1.4.5 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly quoted in the resulting 404 error page.
0
Attacker Value
Unknown
CVE-2004-1492
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Master of Orion III 1.2.5 and earlier allows remote attackers to cause a denial of service (game exit) via a data packet that contains a large size specifier, which causes a large memory allocation to fail.
0