Show filters
268 Total Results
Displaying 91-100 of 268
Sort by:
Attacker Value
Unknown
CVE-2019-12775
Disclosure Date: June 07, 2019 (last updated November 27, 2024)
An issue was discovered on the ENTTEC Datagate MK2, Storm 24, Pixelator, and E-Streamer MK2 with firmware 70044_update_05032019-482. They allow high-privileged root access by www-data via sudo without requiring appropriate access control. (Furthermore, the user account that controls the web application service is granted full access to run any system commands with elevated privilege, without the need for password authentication. Should vulnerabilities be identified and exploited within the web application, it may be possible for a threat actor to create or run high-privileged binaries or executables that are available within the operating system of the device.)
0
Attacker Value
Unknown
CVE-2019-12777
Disclosure Date: June 07, 2019 (last updated November 27, 2024)
An issue was discovered on the ENTTEC Datagate MK2, Storm 24, Pixelator, and E-Streamer MK2 with firmware 70044_update_05032019-482. They replace secure and protected directory permissions (set as default by the underlying operating system) with highly insecure read, write, and execute directory permissions for all users. By default, /usr/local and all of its subdirectories should have permissions set to only allow non-privileged users to read and execute from the tree structure, and to deny users from creating or editing files in this location. The ENTTEC firmware startup script permits all users to read, write, and execute (rwxrwxrwx) from the /usr, /usr/local, /usr/local/dmxis, and /usr/local/bin/ directories.
0
Attacker Value
Unknown
CVE-2019-12774
Disclosure Date: June 07, 2019 (last updated November 27, 2024)
A number of stored XSS vulnerabilities have been identified in the web configuration feature in ENTTEC Datagate Mk2 70044_update_05032019-482 that could allow an unauthenticated threat actor to inject malicious code directly into the application. This affects, for example, the Profile Description field in JSON data to the Profile Editor.
0
Attacker Value
Unknown
CVE-2019-6542
Disclosure Date: March 28, 2019 (last updated November 27, 2024)
ENTTEC Datagate MK2, Storm 24, Pixelator all firmware versions prior to (70044,70050,70060)_update_05032019-482 allows an unauthenticated user to initiate a remote reboot, which may be used to cause a denial of service condition.
0
Attacker Value
Unknown
CVE-2017-12447
Disclosure Date: March 07, 2019 (last updated November 27, 2024)
GdkPixBuf (aka gdk-pixbuf), possibly 2.32.2, as used by GNOME Nautilus 3.14.3 on Ubuntu 16.04, allows attackers to cause a denial of service (stack corruption) or possibly have unspecified other impact via a crafted file folder.
0
Attacker Value
Unknown
CVE-2018-19919
Disclosure Date: December 06, 2018 (last updated November 27, 2024)
Pixelimity 1.0 has Persistent XSS via the admin/portfolio.php data[title] parameter, as demonstrated by a crafted onload attribute of an SVG element.
0
Attacker Value
Unknown
CVE-2018-0606
Disclosure Date: June 26, 2018 (last updated November 26, 2024)
SQL injection vulnerability in the Pixelpost v1.7.3 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown
CVE-2018-0605
Disclosure Date: June 26, 2018 (last updated November 26, 2024)
Cross-site scripting vulnerability in Pixelpost v1.7.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2018-0604
Disclosure Date: June 26, 2018 (last updated November 26, 2024)
Pixelpost v1.7.3 and earlier allows remote code execution via unspecified vectors.
0
Attacker Value
Unknown
CVE-2018-0578
Disclosure Date: May 14, 2018 (last updated November 26, 2024)
Cross-site scripting vulnerability in PixelYourSite plugin prior to version 5.3.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0