Show filters
2 Total Results
Displaying 1-2 of 2
Sort by:
Attacker Value
Very Low
Supra Smart Cloud TV Remote File Inclusion
Disclosure Date: September 11, 2019 (last updated November 27, 2024)
Supra Smart Cloud TV allows remote file inclusion in the openLiveURL function, which allows a local attacker to broadcast fake video without any authentication via a /remote/media_control?action=setUri&uri= URI.
0
Attacker Value
Unknown
CVE-2022-3853
Disclosure Date: December 12, 2022 (last updated October 08, 2023)
Cross-site Scripting (XSS) is a client-side code injection attack. The attacker aims to execute malicious scripts in a web browser of the victim by including malicious code in a legitimate web page or web application.
0