|
224581
|
6.5 |
MEDIUM
Network
|
maxum
|
rumpus
|
A CSRF vulnerability exists in the Web File Manager's Network Setting functionality of Rumpus FTP Server 8.2.9.1. By exploiting it, an attacker can manipulate the SMTP setting and other network setti…
|
CWE-352
Origin Validation Error
|
CVE-2019-19660
|
2024-11-21 13:35 |
2020-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224582
|
8.8 |
HIGH
Network
|
maxum
|
rumpus
|
A CSRF vulnerability exists in the Web File Manager's Edit Accounts functionality of Rumpus FTP Server 8.2.9.1. By exploiting it, an attacker can take over a user account by changing the password, up…
|
CWE-352
Origin Validation Error
|
CVE-2019-19659
|
2024-11-21 13:35 |
2020-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224583
|
5.3 |
MEDIUM
Network
|
zohocorp
|
manageengine_applications_manager
|
Zoho ManageEngine Applications Manager 14 before 14520 allows a remote unauthenticated attacker to disclose OS file names via FailOverHelperServlet.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-19800
|
2024-11-21 13:35 |
2020-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224584
|
5.4 |
MEDIUM
Network
|
pandorafms
|
pandora_fms
|
PandoraFMS 742 suffers from multiple XSS vulnerabilities, affecting the Agent Management, Report Builder, and Graph Builder components. An authenticated user can inject dangerous content into a data …
|
CWE-79
Cross-site Scripting
|
CVE-2019-19968
|
2024-11-21 13:35 |
2020-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224585
|
8.8 |
HIGH
Network
|
totolink
|
a3002ru_firmware a702r_firmware n301rt_firmware n302r_firmware n300rt_firmware n200re_firmware n150rt_firmware n100re_firmware
|
On certain TOTOLINK Realtek SDK based routers, an authenticated attacker may execute arbitrary OS commands via the sysCmd parameter to the boafrm/formSysCmd URI, even if the GUI (syscmd.htm) is not a…
|
CWE-78
OS Command
|
CVE-2019-19824
|
2024-11-21 13:35 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224586
|
7.5 |
HIGH
Network
|
totolink realtek sapido ciktel kctvjeju fg-products hiwifi tbroad coship iodata hcn_max-c300n_project
|
a3002ru_firmware a702r_firmware n302r_firmware n300rt_firmware n200re_firmware n150rt_firmware n100re_firmware rtk_11n_ap_firmware gr297n_firmware mesh_router_firmware w…
|
A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext administrative passwords in flash memory and in a file. This affects TOTOLINK A3002R…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-19823
|
2024-11-21 13:35 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224587
|
7.5 |
HIGH
Network
|
totolink realtek sapido ciktel kctvjeju fg-products hiwifi tbroad coship iodata hcn_max-c300n_project
|
a3002ru_firmware a702r_firmware n302r_firmware n300rt_firmware n200re_firmware n150rt_firmware n100re_firmware rtk_11n_ap_firmware gr297n_firmware mesh_router_firmware w…
|
A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) allows remote attackers to retrieve the configuration, including sensitive data (usernames and passwo…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-19822
|
2024-11-21 13:35 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224588
|
9.8 |
CRITICAL
Network
|
totolink
|
a3002ru_firmware a702r_firmware n301rt_firmware n302r_firmware n300rt_firmware n200re_firmware n150rt_firmware n100re_firmware
|
On certain TOTOLINK Realtek SDK based routers, the CAPTCHA text can be retrieved via an {"topicurl":"setting/getSanvas"} POST to the boafrm/formLogin URI, leading to a CAPTCHA bypass. (Also, the CAPT…
|
CWE-287
Improper Authentication
|
CVE-2019-19825
|
2024-11-21 13:35 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224589
|
8.8 |
HIGH
Network
|
bigswitch
|
big_cloud_fabric big_monitoring_fabric multi-cloud_director
|
An issue was discovered in Big Switch Big Monitoring Fabric 6.2 through 6.2.4, 6.3 through 6.3.9, 7.0 through 7.0.3, and 7.1 through 7.1.3; Big Cloud Fabric 4.5 through 4.5.5, 4.7 through 4.7.7, 5.0 …
|
CWE-200
Information Exposure
|
CVE-2019-19631
|
2024-11-21 13:35 |
2020-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224590
|
6.1 |
MEDIUM
Network
|
bigswitch
|
big_cloud_fabric big_monitoring_fabric multi-cloud_director
|
An issue was discovered in Big Switch Big Monitoring Fabric 6.2 through 6.2.4, 6.3 through 6.3.9, 7.0 through 7.0.3, and 7.1 through 7.1.3; Big Cloud Fabric 4.5 through 4.5.5, 4.7 through 4.7.7, 5.0 …
|
CWE-79
Cross-site Scripting
|
CVE-2019-19632
|
2024-11-21 13:35 |
2020-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|