Show filters
15 Total Results
Displaying 1-10 of 15
Sort by:
Attacker Value
Unknown

CVE-2018-12319

Disclosure Date: December 04, 2018 (last updated November 27, 2024)
Denial-of-service in the login page of ASUSTOR ADM 3.1.1 allows attackers to prevent users from signing in by placing malformed text in the title.
0
Attacker Value
Unknown

CVE-2018-12307

Disclosure Date: December 04, 2018 (last updated November 27, 2024)
OS command injection in user.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root via the "name" POST parameter.
0
Attacker Value
Unknown

CVE-2018-12315

Disclosure Date: December 04, 2018 (last updated November 27, 2024)
Missing verification of a password in ASUSTOR ADM version 3.1.1 allows attackers to change account passwords without entering the current password.
0
Attacker Value
Unknown

CVE-2018-12313

Disclosure Date: December 04, 2018 (last updated November 27, 2024)
OS command injection in snmp.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands without authentication via the "rocommunity" URL parameter.
0
Attacker Value
Unknown

CVE-2018-12309

Disclosure Date: December 04, 2018 (last updated November 27, 2024)
Directory Traversal in upload.cgi in ASUSTOR ADM version 3.1.1 allows attackers to upload files to arbitrary locations by modifying the "path" URL parameter. NOTE: the "filename" POST parameter is covered by CVE-2018-11345.
0
Attacker Value
Unknown

CVE-2018-12318

Disclosure Date: December 04, 2018 (last updated November 27, 2024)
Information disclosure in the SNMP settings page in ASUSTOR ADM version 3.1.1 allows attackers to obtain the SNMP password in cleartext.
0
Attacker Value
Unknown

CVE-2018-12311

Disclosure Date: December 04, 2018 (last updated November 27, 2024)
Cross-site scripting vulnerability in File Explorer in ASUSTOR ADM version 3.1.1 allows attackers to execute arbitrary JavaScript when a file is moved via a malicious filename.
0
Attacker Value
Unknown

CVE-2018-12317

Disclosure Date: December 04, 2018 (last updated November 27, 2024)
OS command injection in group.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root by modifying the "name" POST parameter.
0
Attacker Value
Unknown

CVE-2018-12305

Disclosure Date: December 04, 2018 (last updated November 27, 2024)
Cross-site scripting in File Explorer in ASUSTOR ADM version 3.1.1 allows attackers to execute JavaScript by uploading SVG images with embedded JavaScript.
0
Attacker Value
Unknown

CVE-2018-12316

Disclosure Date: December 04, 2018 (last updated November 27, 2024)
OS Command Injection in upload.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands by modifying the filename POST parameter.
0