|
225481
|
5.4 |
MEDIUM
Network
|
maxum
|
rumpus_ftp
|
A CSRF vulnerability exists in the Block Clients component of Web File Manager in Rumpus FTP 8.2.9.1 that could allow an attacker to whitelist or block any IP address via RAPR/BlockedClients.html.
|
CWE-352
Origin Validation Error
|
CVE-2019-19667
|
2024-11-21 13:35 |
2020-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225482
|
4.3 |
MEDIUM
Network
|
maxum
|
rumpus_ftp
|
A CSRF vulnerability exists in the Event Notices Settings of Web File Manager in Rumpus FTP 8.2.9.1. An attacker can create/update event notices via RAPR/EventNoticesSet.html.
|
CWE-352
Origin Validation Error
|
CVE-2019-19666
|
2024-11-21 13:35 |
2020-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225483
|
6.1 |
MEDIUM
Network
|
maxum
|
rumpus_ftp
|
A Cookie based reflected XSS exists in the Web File Manager of Rumpus FTP Server 8.2.9.1, related to RumpusLoginUserName and snp.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19661
|
2024-11-21 13:35 |
2020-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225484
|
7.1 |
HIGH
Network
|
maxum
|
rumpus_ftp
|
A CSRF vulnerability exists in the Web Settings of Web File Manager in Rumpus FTP 8.2.9.1. Exploitation of this vulnerability can result in manipulation of Server Web settings at RAPR/WebSettingsGene…
|
CWE-352
Origin Validation Error
|
CVE-2019-19664
|
2024-11-21 13:35 |
2020-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225485
|
6.5 |
MEDIUM
Network
|
maxum
|
rumpus_ftp
|
A CSRF vulnerability exists in the Web File Manager's Create/Delete Accounts functionality of Rumpus FTP Server 8.2.9.1. By exploiting it, an attacker can Create and Delete accounts via RAPR/TriggerS…
|
CWE-352
Origin Validation Error
|
CVE-2019-19662
|
2024-11-21 13:35 |
2020-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225486
|
6.5 |
MEDIUM
Network
|
maxum
|
rumpus
|
A CSRF vulnerability exists in the FTP Settings of Web File Manager in Rumpus FTP 8.2.9.1. Exploitation of this vulnerability can result in manipulation of Server FTP settings at RAPR/FTPSettingsSet.…
|
CWE-352
Origin Validation Error
|
CVE-2019-19665
|
2024-11-21 13:35 |
2020-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225487
|
6.5 |
MEDIUM
Network
|
maxum
|
rumpus
|
A CSRF vulnerability exists in the Folder Sets Settings of Web File Manager in Rumpus FTP 8.2.9.1. This allows an attacker to Create/Delete Folders after exploiting it at RAPR/FolderSetsSet.html.
|
CWE-352
Origin Validation Error
|
CVE-2019-19663
|
2024-11-21 13:35 |
2020-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225488
|
6.5 |
MEDIUM
Network
|
maxum
|
rumpus
|
A CSRF vulnerability exists in the Web File Manager's Network Setting functionality of Rumpus FTP Server 8.2.9.1. By exploiting it, an attacker can manipulate the SMTP setting and other network setti…
|
CWE-352
Origin Validation Error
|
CVE-2019-19660
|
2024-11-21 13:35 |
2020-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225489
|
8.8 |
HIGH
Network
|
maxum
|
rumpus
|
A CSRF vulnerability exists in the Web File Manager's Edit Accounts functionality of Rumpus FTP Server 8.2.9.1. By exploiting it, an attacker can take over a user account by changing the password, up…
|
CWE-352
Origin Validation Error
|
CVE-2019-19659
|
2024-11-21 13:35 |
2020-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225490
|
5.3 |
MEDIUM
Network
|
zohocorp
|
manageengine_applications_manager
|
Zoho ManageEngine Applications Manager 14 before 14520 allows a remote unauthenticated attacker to disclose OS file names via FailOverHelperServlet.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-19800
|
2024-11-21 13:35 |
2020-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|