Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
Unknown

CVE-2024-5409

Disclosure Date: May 27, 2024 (last updated May 28, 2024)
RhinOS 3.0-1190 is vulnerable to an XSS via the "tamper" parameter in /admin/lib/phpthumb/phpthumb.php. An attacker could create a malicious URL and send it to a victim to obtain their session details.
0
Attacker Value
Unknown

CVE-2024-5408

Disclosure Date: May 27, 2024 (last updated May 28, 2024)
Vulnerability in RhinOS 3.0-1190 consisting of an XSS through the "search" parameter of /portal/search.htm. This vulnerability could allow a remote attacker to steal details of a victim's user session by submitting a specially crafted URL.
0
Attacker Value
Unknown

CVE-2024-5407

Disclosure Date: May 27, 2024 (last updated May 28, 2024)
A vulnerability in RhinOS 3.0-1190 could allow PHP code injection through the "search" parameter in /portal/search.htm. This vulnerability could allow a remote attacker to perform a reverse shell on the remote system, compromising the entire infrastructure.
0
Attacker Value
Unknown

CVE-2019-19458

Disclosure Date: December 03, 2019 (last updated November 27, 2024)
SALTO ProAccess SPACE 5.4.3.0 allows Directory Traversal in the Data Export feature.
Attacker Value
Unknown

CVE-2019-19457

Disclosure Date: December 03, 2019 (last updated November 27, 2024)
SALTO ProAccess SPACE 5.4.3.0 allows XSS.
Attacker Value
Unknown

CVE-2019-19460

Disclosure Date: December 03, 2019 (last updated November 27, 2024)
An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. The product's webserver runs as a Windows service with local SYSTEM permissions by default. This is against the principle of least privilege. An attacker who is able to exploit CVE-2019-19458 or CVE-2019-19459 is basically able to write to every single path on the file system, because the webserver is running with the highest privileges available.
Attacker Value
Unknown

CVE-2019-19459

Disclosure Date: August 07, 2019 (last updated November 27, 2024)
An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. An attacker can write arbitrary content to arbitrary files, as demonstrated by CVE-2019-19458 files under the web root, or .bat files that will be used with auto start. This allows an attacker to execute arbitrary commands on the server.
Attacker Value
Unknown

CVE-2018-18762

Disclosure Date: March 21, 2019 (last updated November 27, 2024)
SaltOS 3.1 r8126 contains a database download vulnerability.
0
Attacker Value
Unknown

CVE-2018-18760

Disclosure Date: November 16, 2018 (last updated November 27, 2024)
RhinOS 3.0 build 1190 allows CSRF.
0
Attacker Value
Unknown

CVE-2018-18761

Disclosure Date: November 16, 2018 (last updated November 27, 2024)
SaltOS 3.1 r8126 allows action=login&querystring=&user=[SQL] SQL Injection.