Show filters
37 Total Results
Displaying 1-10 of 37
Sort by:
Attacker Value
Unknown
CVE-2022-31517
Disclosure Date: July 11, 2022 (last updated October 07, 2023)
The HolgerGraef/MSM repository through 2021-04-20 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
0
Attacker Value
Unknown
CVE-2022-26988
Disclosure Date: May 10, 2022 (last updated February 23, 2025)
TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MntAte` function. Local users could get remote code execution.
0
Attacker Value
Unknown
CVE-2022-26987
Disclosure Date: May 10, 2022 (last updated February 23, 2025)
TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MmtAtePrase` function. Local users could get remote code execution.
0
Attacker Value
Unknown
CVE-2021-25810
Disclosure Date: April 29, 2021 (last updated February 22, 2025)
Cross site Scripting (XSS) vulnerability in MERCUSYS Mercury X18G 1.0.5 devices, via crafted values to the 'src_dport_start', 'src_dport_end', and 'dest_port' parameters.
0
Attacker Value
Unknown
CVE-2021-25811
Disclosure Date: April 29, 2021 (last updated November 28, 2024)
MERCUSYS Mercury X18G 1.0.5 devices allow Denial of service via a crafted value to the POST listen_http_lan parameter. Upon subsequent device restarts after this vulnerability is exploted the device will not be able to access the webserver unless the listen_http_lan parameter to uhttpd.json is manually fixed.
0
Attacker Value
Unknown
CVE-2021-23242
Disclosure Date: January 07, 2021 (last updated February 22, 2025)
MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ to the UPnP server, as demonstrated by the /../../conf/template/uhttpd.json URI.
0
Attacker Value
Unknown
CVE-2021-23241
Disclosure Date: January 07, 2021 (last updated February 22, 2025)
MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ in conjunction with a loginLess or login.htm URI (for authentication bypass) to the web server, as demonstrated by the /loginLess/../../etc/passwd URI.
0
Attacker Value
Unknown
CVE-2020-10990
Disclosure Date: March 27, 2020 (last updated February 21, 2025)
An XXE issue exists in Accenture Mercury before 1.12.28 because of the platformlambda/core/serializers/SimpleXmlParser.java component.
0
Attacker Value
Unknown
CVE-2010-1959
Disclosure Date: May 27, 2010 (last updated October 04, 2023)
Unspecified vulnerability in HP TestDirector for Quality Center 9.2 before Patch8 allows remote attackers to modify data via unknown vectors.
0
Attacker Value
Unknown
CVE-2008-6632
Disclosure Date: April 07, 2009 (last updated October 04, 2023)
SQL injection vulnerability in func/login.php in MercuryBoard 1.1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header ($_SERVER['HTTP_USER_AGENT']).
0