Show filters
114 Total Results
Displaying 61-70 of 114
Sort by:
Attacker Value
Unknown

CVE-2021-30003

Disclosure Date: April 02, 2021 (last updated February 22, 2025)
An issue was discovered on Nokia G-120W-F 3FE46606AGAB91 devices. There is Stored XSS in the administrative interface via urlfilter.cgi?add url_address.
Attacker Value
Unknown

CVE-2021-26597

Disclosure Date: March 25, 2021 (last updated February 22, 2025)
An issue was discovered in Nokia NetAct 18A. A remote user, authenticated to the NOKIA NetAct Web Page, can visit the Site Configuration Tool web site section and arbitrarily upload potentially dangerous files without restrictions via the /netact/sct dir parameter in conjunction with the operation=upload value.
Attacker Value
Unknown

CVE-2021-26596

Disclosure Date: March 25, 2021 (last updated February 22, 2025)
An issue was discovered in Nokia NetAct 18A. A malicious user can change a filename of an uploaded file to include JavaScript code, which is then stored and executed by a victim's web browser. The most common mechanism for delivering malicious content is to include it as a parameter in a URL that is posted publicly or e-mailed directly to victims. Here, the /netact/sct filename parameter is used.
Attacker Value
Unknown

CVE-2014-3809

Disclosure Date: January 31, 2020 (last updated February 21, 2025)
Cross-site scripting (XSS) vulnerability in the management interface in Alcatel-Lucent 1830 Photonic Service Switch (PSS) 6.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the myurl parameter to menu/pop.html.
Attacker Value
Unknown

CVE-2019-17405

Disclosure Date: November 25, 2019 (last updated November 27, 2024)
Nokia IMPACT < 18A: has Reflected self XSS
Attacker Value
Unknown

CVE-2019-17403

Disclosure Date: November 25, 2019 (last updated November 27, 2024)
Nokia IMPACT < 18A: An unrestricted File Upload vulnerability was found that may lead to Remote Code Execution.
Attacker Value
Unknown

CVE-2019-17404

Disclosure Date: November 25, 2019 (last updated November 27, 2024)
Nokia IMPACT < 18A: allows full path disclosure
Attacker Value
Unknown

CVE-2019-17406

Disclosure Date: March 28, 2019 (last updated November 27, 2024)
Nokia IMPACT < 18A has path traversal that may lead to RCE if chained with CVE-2019-1743
Attacker Value
Unknown

CVE-2019-7386

Disclosure Date: March 21, 2019 (last updated November 27, 2024)
A Denial of Service issue has been discovered in the Gecko component of KaiOS 2.5 10.05 (platform 48.0.a2) on Nokia 8810 4G devices. When a crafted web page is visited with the internal browser, the Gecko process crashes with a segfault. Successful exploitation could lead to the remote code execution on the device.
0
Attacker Value
Unknown

CVE-2019-3920

Disclosure Date: March 05, 2019 (last updated November 27, 2024)
The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to authenticated command injection via crafted HTTP request sent by a remote, authenticated attacker to /GponForm/device_Form?script/.