|
199791
|
5.3 |
MEDIUM
Network
|
canto
|
canto
|
The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and external server via /includes/lib/get.php?subdomai…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-28977
|
2024-11-21 14:23 |
2020-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199792
|
5.3 |
MEDIUM
Network
|
canto
|
canto
|
The Canto plugin 1.3.0 for WordPress contains a blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and external server via /includes/lib/detail.php?sub…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-28976
|
2024-11-21 14:23 |
2020-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199793
|
9.8 |
CRITICAL
Network
|
fujitsu
|
eternus_storage_dx200_s4_firmware
|
An issue was discovered on Fujitsu Eternus Storage DX200 S4 devices through 2020-11-25. After logging into the portal as a root user (using any web browser), the portal can be accessed with root priv…
|
CWE-287
Improper Authentication
|
CVE-2020-29127
|
2024-11-21 14:23 |
2020-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199794
|
7.8 |
HIGH
Local
|
vsolcn
|
v1600d4l_firmware v1600d-mini_firmware
|
An issue was discovered on V-SOL V1600D4L V1.01.49 and V1600D-MINI V1.01.48 OLT devices. A hardcoded RSA private key (specific to V1600D4L and V1600D-MINI) is contained in the firmware images.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-29383
|
2024-11-21 14:23 |
2020-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199795
|
7.8 |
HIGH
Local
|
vsolcn
|
v1600d_firmware v1600g1_firmware v1600g2_firmware
|
An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4 OLT devices. A hardcoded RSA private key (specific to V1600D, V1600G1, and V1600G2) is con…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-29382
|
2024-11-21 14:23 |
2020-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199796
|
9.8 |
CRITICAL
Network
|
vsolcn
|
v1600d_firmware v1600d4l_firmware v1600d-mini_firmware v1600g1_firmware v1600g2_firmware
|
An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4 OLT devices. Command injection can occur in "uplo…
|
CWE-78
OS Command
|
CVE-2020-29381
|
2024-11-21 14:23 |
2020-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199797
|
5.9 |
MEDIUM
Network
|
vsolcn
|
v1600d_firmware v1600d4l_firmware v1600d-mini_firmware v1600g1_firmware v1600g2_firmware
|
An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4 OLT devices. TELNET is offered by default but SSH…
|
CWE-319 CWE-522
Cleartext Transmission of Sensitive Information Insufficiently Protected Credentials
|
CVE-2020-29380
|
2024-11-21 14:23 |
2020-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199798
|
5.5 |
MEDIUM
Local
|
vsolcn
|
v1600d4l_firmware v1600d-mini_firmware
|
An issue was discovered on V-SOL V1600D4L V1.01.49 and V1600D-MINI V1.01.48 OLT devices. During the process of updating the firmware, the update script starts a telnetd -l /bin/sh process that does n…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-29379
|
2024-11-21 14:23 |
2020-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199799
|
8.8 |
HIGH
Network
|
vsolcn
|
v1600d_firmware v1600d4l_firmware v1600d-mini_firmware v1600g1_firmware v1600g2_firmware
|
An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4 OLT devices. It is possible to elevate the privil…
|
CWE-287
Improper Authentication
|
CVE-2020-29378
|
2024-11-21 14:23 |
2020-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199800
|
9.8 |
CRITICAL
Network
|
vsolcn
|
v1600d_firmware
|
An issue was discovered on V-SOL V1600D V2.03.69 OLT devices. The string K0LTdi@gnos312$ is compared to the password provided by the the remote attacker. If it matches, access is provided.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-29377
|
2024-11-21 14:23 |
2020-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|