Show filters
27 Total Results
Displaying 1-10 of 27
Sort by:
Attacker Value
Unknown

CVE-2020-6627

Disclosure Date: December 06, 2022 (last updated October 08, 2023)
The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_backend_launch in cirrus/application/helpers/mv_backend_helper.php by leveraging the "start" state and sending a check_device_name request.
Attacker Value
Unknown

CVE-2021-43429

Disclosure Date: April 07, 2022 (last updated October 07, 2023)
A Denial of Service vulnerability exists in CORTX-S3 Server as of 11/7/2021 via the mempool_destroy method due to a failture to release locks pool->lock.
Attacker Value
Unknown

CVE-2018-12300

Disclosure Date: May 13, 2019 (last updated November 27, 2024)
Arbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclose information in the Referer header via the 'state' URL parameter.
0
Attacker Value
Unknown

CVE-2018-12304

Disclosure Date: May 13, 2019 (last updated November 27, 2024)
Cross-site scripting in Application Manager in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via multiple application metadata fields: Short Description, Publisher Name, Publisher Contact, or Website URL.
0
Attacker Value
Unknown

CVE-2018-12298

Disclosure Date: May 13, 2019 (last updated November 27, 2024)
Directory Traversal in filebrowser in Seagate NAS OS 4.3.15.1 allows attackers to read files within the application's container via a URL path.
0
Attacker Value
Unknown

CVE-2018-12296

Disclosure Date: May 13, 2019 (last updated November 27, 2024)
Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attackers to obtain information about the NAS without authentication via empty POST requests.
0
Attacker Value
Unknown

CVE-2018-12302

Disclosure Date: May 13, 2019 (last updated November 27, 2024)
Missing HTTPOnly flag on session cookies in the Seagate NAS OS version 4.3.15.1 web application allows attackers to steal session tokens via cross-site scripting.
0
Attacker Value
Unknown

CVE-2018-12299

Disclosure Date: May 13, 2019 (last updated November 27, 2024)
Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via uploaded file names.
0
Attacker Value
Unknown

CVE-2018-12303

Disclosure Date: May 13, 2019 (last updated November 27, 2024)
Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via directory names.
0
Attacker Value
Unknown

CVE-2018-12301

Disclosure Date: May 13, 2019 (last updated November 27, 2024)
Unvalidated URL in Download Manager in Seagate NAS OS version 4.3.15.1 allows attackers to access the loopback interface via a Download URL of 127.0.0.1 or localhost.
0