Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown

CVE-2019-20070

Disclosure Date: December 30, 2019 (last updated November 27, 2024)
On Netis DL4323 devices, XSS exists via the urlFQDN parameter to form2url.cgi (aka the Keyword field of the URL Blocking Configuration).
Attacker Value
Unknown

CVE-2019-20075

Disclosure Date: December 30, 2019 (last updated November 27, 2024)
On Netis DL4323 devices, pingrtt_v6.html has XSS (Ping6 Diagnostic).
Attacker Value
Unknown

CVE-2019-20074

Disclosure Date: December 30, 2019 (last updated November 27, 2024)
On Netis DL4323 devices, any user role can view sensitive information, such as a user password or the FTP password, via the form2saveConf.cgi page.
Attacker Value
Unknown

CVE-2019-20076

Disclosure Date: December 30, 2019 (last updated November 27, 2024)
On Netis DL4323 devices, XSS exists via the form2Ddns.cgi username parameter (DynDns settings of the Dynamic DNS Configuration).
Attacker Value
Unknown

CVE-2019-20071

Disclosure Date: December 30, 2019 (last updated November 27, 2024)
On Netis DL4323 devices, CSRF exists via form2logaction.cgi to delete all logs.
Attacker Value
Unknown

CVE-2019-20073

Disclosure Date: December 30, 2019 (last updated November 27, 2024)
On Netis DL4323 devices, XSS exists via the form2userconfig.cgi username parameter (User Account Configuration).
Attacker Value
Unknown

CVE-2019-20072

Disclosure Date: December 30, 2019 (last updated November 27, 2024)
On Netis DL4323 devices, XSS exists via the form2Ddns.cgi hostname parameter (Dynamic DNS Configuration).