Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown
CVE-2024-0522
Disclosure Date: January 14, 2024 (last updated January 23, 2024)
A vulnerability was found in Allegro RomPager 4.01. It has been classified as problematic. Affected is an unknown function of the file usertable.htm?action=delete of the component HTTP POST Request Handler. The manipulation of the argument username leads to cross-site request forgery. It is possible to launch the attack remotely. Upgrading to version 4.30 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-250692. NOTE: The vendor explains that this is a very old issue that got fixed 20 years ago but without a public disclosure.
0
Attacker Value
Unknown
CVE-2023-25392
Disclosure Date: April 10, 2023 (last updated October 08, 2023)
Allegro Tech BigFlow <1.6 is vulnerable to Missing SSL Certificate Validation.
0
Attacker Value
Unknown
CVE-2021-43978
Disclosure Date: December 08, 2021 (last updated February 23, 2025)
Allegro WIndows 3.3.4152.0, embeds software administrator database credentials into its binary files, which allows users to access and modify data using the same credentials.
0
Attacker Value
Unknown
CVE-2021-42110
Disclosure Date: December 08, 2021 (last updated October 07, 2023)
An issue was discovered in Allegro Windows (formerly Popsy Windows) before 3.3.4156.1. A standard user can escalate privileges to SYSTEM if the FTP module is installed, because of DLL hijacking.
0
Attacker Value
Unknown
CVE-2014-9222
Disclosure Date: December 24, 2014 (last updated October 05, 2023)
AllegroSoft RomPager 4.34 and earlier, as used in Huawei Home Gateway products and other vendors and products, allows remote attackers to gain privileges via a crafted cookie that triggers memory corruption, aka the "Misfortune Cookie" vulnerability.
0
Attacker Value
Unknown
CVE-2014-9223
Disclosure Date: December 24, 2014 (last updated October 05, 2023)
Multiple buffer overflows in AllegroSoft RomPager, as used in Huawei Home Gateway products and other vendors and products, allow remote attackers to cause a denial of service or possibly execute arbitrary code via unspecified vectors related to authorization.
0
Attacker Value
Unknown
CVE-2013-6786
Disclosure Date: January 16, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Allegro RomPager before 4.51, as used on the ZyXEL P660HW-D1, Huawei MT882, Sitecom WL-174, TP-LINK TD-8816, and D-Link DSL-2640R and DSL-2641R, when the "forbidden author header" protection mechanism is bypassed, allows remote attackers to inject arbitrary web script or HTML by requesting a nonexistent URI in conjunction with a crafted HTTP Referer header that is not properly handled in a 404 page. NOTE: there is no CVE for a "URL redirection" issue that some sources list separately.
0
Attacker Value
Unknown
CVE-2000-0470
Disclosure Date: June 01, 2000 (last updated February 22, 2025)
Allegro RomPager HTTP server allows remote attackers to cause a denial of service via a malformed authentication request.
0