Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown

CVE-2021-20710

Disclosure Date: April 26, 2021 (last updated November 28, 2024)
Cross-site scripting vulnerability in Aterm WG2600HS firmware Ver1.5.1 and earlier allows remote attackers to inject an arbitrary script via unspecified vectors.
Attacker Value
Unknown

CVE-2021-20620

Disclosure Date: January 28, 2021 (last updated November 28, 2024)
Cross-site scripting vulnerability in Aterm WF800HP firmware Ver1.0.9 and earlier allows remote attackers to inject an arbitrary script via unspecified vectors.
Attacker Value
Unknown

CVE-2021-20622

Disclosure Date: January 28, 2021 (last updated November 28, 2024)
Cross-site scripting vulnerability in Aterm WG2600HP firmware Ver1.0.2 and earlier, and Aterm WG2600HP2 firmware Ver1.0.2 and earlier allows remote attackers to inject an arbitrary script via unspecified vectors.
Attacker Value
Unknown

CVE-2021-20621

Disclosure Date: January 28, 2021 (last updated November 28, 2024)
Cross-site request forgery (CSRF) vulnerability in Aterm WG2600HP firmware Ver1.0.2 and earlier, and Aterm WG2600HP2 firmware Ver1.0.2 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
Attacker Value
Unknown

CVE-2017-12575

Disclosure Date: August 24, 2018 (last updated November 27, 2024)
An issue was discovered on the NEC Aterm WG2600HP2 1.0.2. The router has a set of web service APIs for access to and setup of the configuration. Some APIs don't require authentication. An attacker could exploit this vulnerability by sending a crafted HTTP request to retrieve DHCP clients, firmware version, and network status (ex.: curl -X http://[IP]/aterm_httpif.cgi/negotiate -d "REQ_ID=SUPPORT_IF_GET").
0
Attacker Value
Unknown

CVE-2016-1167

Disclosure Date: April 01, 2016 (last updated November 25, 2024)
Cross-site request forgery (CSRF) vulnerability on NEC Aterm WG300HP devices allows remote attackers to hijack the authentication of arbitrary users.
0
Attacker Value
Unknown

CVE-2016-1168

Disclosure Date: April 01, 2016 (last updated November 25, 2024)
Cross-site request forgery (CSRF) vulnerability on NEC Aterm WF800HP devices with firmware 1.0.17 and earlier allows remote attackers to hijack the authentication of arbitrary users.
0
Attacker Value
Unknown

CVE-2014-8361

Disclosure Date: May 01, 2015 (last updated June 28, 2024)
The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.
Attacker Value
Unknown

CVE-2008-1142

Disclosure Date: April 07, 2008 (last updated October 04, 2023)
rxvt 2.6.4 opens a terminal window on :0 if the DISPLAY environment variable is not set, which might allow local users to hijack X11 connections. NOTE: it was later reported that rxvt-unicode, mrxvt, aterm, multi-aterm, and wterm are also affected. NOTE: realistic attack scenarios require that the victim enters a command on the wrong machine.
0
Attacker Value
Unknown

CVE-2007-2575

Disclosure Date: May 09, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in watermark.php in the vm (aka Jean-Francois Laflamme) watermark 0.4.1 mod for Gallery allows remote attackers to execute arbitrary PHP code via a URL in the GALLERY_BASEDIR parameter.
0