Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown
CVE-2021-38702
Disclosure Date: August 17, 2021 (last updated February 23, 2025)
Cyberoam NetGenie C0101B1-20141120-NG11VO devices through 2021-08-14 allow tweb/ft.php?u=[XSS] attacks.
0
Attacker Value
Unknown
CVE-2015-6811
Disclosure Date: September 04, 2015 (last updated October 05, 2023)
SQL injection vulnerability in the Sophos Cyberoam CR500iNG-XP firewall appliance with CyberoamOS 10.6.2 MR-1 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter to login.xml.
0
Attacker Value
Unknown
CVE-2014-5501
Disclosure Date: October 07, 2014 (last updated October 05, 2023)
Stack-based buffer overflow in the diagnose service in the Sophos Cyberoam appliances with CyberoamOS before 10.6.1 GA allows remote attackers to execute arbitrary code via a crafted webpage or file.
0
Attacker Value
Unknown
CVE-2014-5503
Disclosure Date: October 07, 2014 (last updated October 05, 2023)
SQL injection vulnerability in the Guest Login Portal in the Sophos Cyberoam appliances with CyberoamOS before 10.6.1 GA allows remote attackers to execute arbitrary SQL commands via the add_guest_user opcode.
0
Attacker Value
Unknown
CVE-2014-5502
Disclosure Date: October 07, 2014 (last updated October 05, 2023)
The Sophos Cyberoam appliances with CyberoamOS before 10.6.1 GA allows remote authenticated users to inject arbitrary commands via a (1) checkcert_key, (2) webclient_portal_settings, (3) sslvpn_liveuser_delete, or (4) ccc_flush_sql_file opcode.
0
Attacker Value
Unknown
CVE-2012-1047
Disclosure Date: February 12, 2012 (last updated October 04, 2023)
Directory traversal vulnerability in the WWWHELP Service (js/html/wwhelp.htm) in Cyberoam Central Console (CCC) 2.00.2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the file parameter in an Online_help action.
0