Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown

CVE-2021-38702

Disclosure Date: August 17, 2021 (last updated February 23, 2025)
Cyberoam NetGenie C0101B1-20141120-NG11VO devices through 2021-08-14 allow tweb/ft.php?u=[XSS] attacks.
Attacker Value
Unknown

CVE-2015-6811

Disclosure Date: September 04, 2015 (last updated October 05, 2023)
SQL injection vulnerability in the Sophos Cyberoam CR500iNG-XP firewall appliance with CyberoamOS 10.6.2 MR-1 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter to login.xml.
0
Attacker Value
Unknown

CVE-2014-5501

Disclosure Date: October 07, 2014 (last updated October 05, 2023)
Stack-based buffer overflow in the diagnose service in the Sophos Cyberoam appliances with CyberoamOS before 10.6.1 GA allows remote attackers to execute arbitrary code via a crafted webpage or file.
0
Attacker Value
Unknown

CVE-2014-5503

Disclosure Date: October 07, 2014 (last updated October 05, 2023)
SQL injection vulnerability in the Guest Login Portal in the Sophos Cyberoam appliances with CyberoamOS before 10.6.1 GA allows remote attackers to execute arbitrary SQL commands via the add_guest_user opcode.
0
Attacker Value
Unknown

CVE-2014-5502

Disclosure Date: October 07, 2014 (last updated October 05, 2023)
The Sophos Cyberoam appliances with CyberoamOS before 10.6.1 GA allows remote authenticated users to inject arbitrary commands via a (1) checkcert_key, (2) webclient_portal_settings, (3) sslvpn_liveuser_delete, or (4) ccc_flush_sql_file opcode.
0
Attacker Value
Unknown

CVE-2012-1047

Disclosure Date: February 12, 2012 (last updated October 04, 2023)
Directory traversal vulnerability in the WWWHELP Service (js/html/wwhelp.htm) in Cyberoam Central Console (CCC) 2.00.2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the file parameter in an Online_help action.
0