Show filters
22 Total Results
Displaying 1-10 of 22
Sort by:
Attacker Value
High
CVE-2024-52053
Disclosure Date: November 21, 2024 (last updated January 05, 2025)
Stored Cross-Site Scripting in the Manager component of Wowza Streaming Engine below 4.9.1 allows an unauthenticated attacker to inject client-side JavaScript into the web dashboard to automatically hijack admin accounts.
1
Attacker Value
Moderate
CVE-2024-52052
Disclosure Date: November 21, 2024 (last updated January 05, 2025)
Wowza Streaming Engine below 4.9.1 permits an authenticated Streaming Engine Manager administrator to define a custom application property and poison a stream target for high-privilege remote code execution.
1
Attacker Value
Unknown
CVE-2024-52056
Disclosure Date: November 21, 2024 (last updated January 05, 2025)
Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to delete any directory on the file system if the target directory contains an XML definition file.
0
Attacker Value
Unknown
CVE-2024-52055
Disclosure Date: November 21, 2024 (last updated January 05, 2025)
Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to read any file on the file system if the target directory contains an XML definition file.
0
Attacker Value
Unknown
CVE-2024-52054
Disclosure Date: November 21, 2024 (last updated January 05, 2025)
Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to create an XML definition file anywhere on the file system.
0
Attacker Value
Unknown
CVE-2021-35492
Disclosure Date: October 05, 2021 (last updated February 23, 2025)
Wowza Streaming Engine through 4.8.11+5 could allow an authenticated, remote attacker to exhaust filesystem resources via the /enginemanager/server/vhost/historical.jsdata vhost parameter. This is due to the insufficient management of available filesystem resources. An attacker could exploit this vulnerability through the Virtual Host Monitoring section by requesting random virtual-host historical data and exhausting available filesystem resources. A successful exploit could allow the attacker to cause database errors and cause the device to become unresponsive to web-based management. (Manual intervention is required to free filesystem resources and return the application to an operational state.)
0
Attacker Value
Unknown
CVE-2021-35491
Disclosure Date: October 05, 2021 (last updated February 23, 2025)
A Cross-Site Request Forgery (CSRF) vulnerability in Wowza Streaming Engine through 4.8.11+5 allows a remote attacker to delete a user account via the /enginemanager/server/user/delete.htm userName parameter. The application does not implement a CSRF token for the GET request. This issue was resolved in Wowza Streaming Engine release 4.8.14.
0
Attacker Value
Unknown
CVE-2021-31539
Disclosure Date: April 23, 2021 (last updated February 22, 2025)
Wowza Streaming Engine before 4.8.8.01 (in a default installation) has cleartext passwords stored in the conf/admin.password file. A regular local user is able to read usernames and passwords.
0
Attacker Value
Unknown
CVE-2021-31540
Disclosure Date: April 23, 2021 (last updated February 22, 2025)
Wowza Streaming Engine through 4.8.5 (in a default installation) has incorrect file permissions of configuration files in the conf/ directory. A regular local user is able to read and write to all the configuration files, e.g., modify the application server configuration.
0
Attacker Value
Unknown
CVE-2019-19453
Disclosure Date: August 03, 2020 (last updated February 21, 2025)
Wowza Streaming Engine before 4.8.5 allows XSS (issue 1 of 2). An authenticated user, with access to the proxy license editing is able to insert a malicious payload that will be triggered in the main page of server settings. This issue was resolved in Wowza Streaming Engine 4.8.5.
0