|
222031
|
6.5 |
MEDIUM
Network
|
maxum
|
rumpus_ftp
|
A CSRF vulnerability exists in the Web File Manager's Create/Delete Accounts functionality of Rumpus FTP Server 8.2.9.1. By exploiting it, an attacker can Create and Delete accounts via RAPR/TriggerS…
|
CWE-352
Origin Validation Error
|
CVE-2019-19662
|
2024-11-21 13:35 |
2020-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222032
|
6.5 |
MEDIUM
Network
|
maxum
|
rumpus
|
A CSRF vulnerability exists in the FTP Settings of Web File Manager in Rumpus FTP 8.2.9.1. Exploitation of this vulnerability can result in manipulation of Server FTP settings at RAPR/FTPSettingsSet.…
|
CWE-352
Origin Validation Error
|
CVE-2019-19665
|
2024-11-21 13:35 |
2020-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222033
|
6.5 |
MEDIUM
Network
|
maxum
|
rumpus
|
A CSRF vulnerability exists in the Folder Sets Settings of Web File Manager in Rumpus FTP 8.2.9.1. This allows an attacker to Create/Delete Folders after exploiting it at RAPR/FolderSetsSet.html.
|
CWE-352
Origin Validation Error
|
CVE-2019-19663
|
2024-11-21 13:35 |
2020-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222034
|
6.5 |
MEDIUM
Network
|
maxum
|
rumpus
|
A CSRF vulnerability exists in the Web File Manager's Network Setting functionality of Rumpus FTP Server 8.2.9.1. By exploiting it, an attacker can manipulate the SMTP setting and other network setti…
|
CWE-352
Origin Validation Error
|
CVE-2019-19660
|
2024-11-21 13:35 |
2020-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222035
|
8.8 |
HIGH
Network
|
maxum
|
rumpus
|
A CSRF vulnerability exists in the Web File Manager's Edit Accounts functionality of Rumpus FTP Server 8.2.9.1. By exploiting it, an attacker can take over a user account by changing the password, up…
|
CWE-352
Origin Validation Error
|
CVE-2019-19659
|
2024-11-21 13:35 |
2020-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222036
|
5.3 |
MEDIUM
Network
|
zohocorp
|
manageengine_applications_manager
|
Zoho ManageEngine Applications Manager 14 before 14520 allows a remote unauthenticated attacker to disclose OS file names via FailOverHelperServlet.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-19800
|
2024-11-21 13:35 |
2020-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222037
|
5.4 |
MEDIUM
Network
|
pandorafms
|
pandora_fms
|
PandoraFMS 742 suffers from multiple XSS vulnerabilities, affecting the Agent Management, Report Builder, and Graph Builder components. An authenticated user can inject dangerous content into a data …
|
CWE-79
Cross-site Scripting
|
CVE-2019-19968
|
2024-11-21 13:35 |
2020-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222038
|
8.8 |
HIGH
Network
|
totolink
|
a3002ru_firmware a702r_firmware n301rt_firmware n302r_firmware n300rt_firmware n200re_firmware n150rt_firmware n100re_firmware
|
On certain TOTOLINK Realtek SDK based routers, an authenticated attacker may execute arbitrary OS commands via the sysCmd parameter to the boafrm/formSysCmd URI, even if the GUI (syscmd.htm) is not a…
|
CWE-78
OS Command
|
CVE-2019-19824
|
2024-11-21 13:35 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222039
|
7.5 |
HIGH
Network
|
totolink realtek sapido ciktel kctvjeju fg-products hiwifi tbroad coship iodata hcn_max-c300n_project
|
a3002ru_firmware a702r_firmware n302r_firmware n300rt_firmware n200re_firmware n150rt_firmware n100re_firmware rtk_11n_ap_firmware gr297n_firmware mesh_router_firmware w…
|
A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext administrative passwords in flash memory and in a file. This affects TOTOLINK A3002R…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-19823
|
2024-11-21 13:35 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222040
|
7.5 |
HIGH
Network
|
totolink realtek sapido ciktel kctvjeju fg-products hiwifi tbroad coship iodata hcn_max-c300n_project
|
a3002ru_firmware a702r_firmware n302r_firmware n300rt_firmware n200re_firmware n150rt_firmware n100re_firmware rtk_11n_ap_firmware gr297n_firmware mesh_router_firmware w…
|
A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) allows remote attackers to retrieve the configuration, including sensitive data (usernames and passwo…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-19822
|
2024-11-21 13:35 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|