Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown

CVE-2022-23137

Disclosure Date: May 11, 2022 (last updated October 07, 2023)
ZTE's ZXCDN product has a reflective XSS vulnerability. The attacker could modify the parameters in the content clearing request url, and when a user clicks the url, an XSS attack will be triggered.
Attacker Value
Unknown

CVE-2019-3427

Disclosure Date: November 22, 2019 (last updated November 27, 2024)
The version V6.01.03.01 of ZTE ZXCDN IAMWEB product is impacted by a code injection vulnerability. An attacker could exploit the vulnerability to inject malicious code into the management page, resulting in users’ information leakage.
Attacker Value
Unknown

CVE-2019-3428

Disclosure Date: November 22, 2019 (last updated November 27, 2024)
The version V6.01.03.01 of ZTE ZXCDN IAMWEB product is impacted by a configuration error vulnerability. An attacker could directly access the management portal in HTTP, resulting in users’ information leakage.
Attacker Value
Unknown

CVE-2017-10936

Disclosure Date: July 25, 2018 (last updated November 27, 2024)
SQL injection vulnerability in all versions prior to V4.01.01 of the ZTE ZXCDN-SNS product allows remote attackers to execute arbitrary SQL commands via the aoData parameter, resulting in the disclosure of database information.
0