CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
M7350_firmware, M7350, Tl-wr840n_firmware, Tl-wr840n, Archer_c3200_v1_firmware, Archer_c3200_v1, Archer_c2_v1_firmware, Archer_c2_v1, Archer_c1200_firmware, Archer_c1200
2019-05-29
N/A
4.8 MEDIUM
TP-Link TL-WR840N v5 00000005 devices allow XSS via the network name. The attacker must log into the router by breaking the password and going to the admin login page by THC-HYDRA to get the network name. With an XSS payload, the network name changed automatically and the internet connection was disconnected. All the users become disconnected from the internet.
H3C H3Cloud OS all versions allows SQL injection via the ear/grid_event sidx parameter.
XSS was discovered in CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.747 via the testacc/fileManager2.php fm_current_dir or filename parameter.
An information disclosure vulnerability exists when the Windows Transaction Manager improperly handles objects in memory, aka 'Windows Transaction Manager Information Disclosure Vulnerability'.
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do search field.
An issue was discovered in Sylius products. Missing input sanitization in sylius/sylius 1.0.x through 1.0.18, 1.1.x through 1.1.17, 1.2.x through 1.2.16, 1.3.x through 1.3.11, and 1.4.x through 1.4.3 and sylius/grid 1.0.x through 1.0.18, 1.1.x through 1.1.18, 1.2.x through 1.2.17, 1.3.x through 1.3.12, 1.4.x through 1.4.4, and 1.5.0 allows an attacker (an admin in the sylius/sylius case) to perform XSS by injecting malicious code into a field displayed in a grid with the "string" field type. The contents are an object, with malicious code returned by the __toString() method of that object.
eLabFTW 1.8.5 is vulnerable to arbitrary file uploads via the /app/controllers/EntityController.php component. This may result in remote command execution. An attacker can use a user account to fully compromise the system using a POST request. This will allow for PHP files to be written to the web root, and for code to execute on the remote server.
There is XSS in browser/components/MarkdownPreview.js in BoostIO Boostnote 0.11.15 via a label named flowchart, sequence, gallery, or chart, as demonstrated by a crafted SRC attribute of an IFRAME element, a different vulnerability than CVE-2019-12136.
Ta-8010_firmware, Ta-8010, Ta-8015_firmware, Ta-8015, Ta-8020_firmware, Ta-8020, Ta-8025_firmware, Ta-8025, Ta-8030_firmware, Ta-8030
2020-03-13
N/A
7.5 HIGH
Incorrect Access Control in Safescan Timemoto TM-616 and TA-8000 series allows remote attackers to read any file via the administrative API.
Ta-8010_firmware, Ta-8010, Ta-8015_firmware, Ta-8015, Ta-8020_firmware, Ta-8020, Ta-8025_firmware, Ta-8025, Ta-8030_firmware, Ta-8030
2020-03-20
N/A
9.8 CRITICAL
Directory Traversal in Safescan Timemoto and TA-8000 series version 1.0 allows unauthenticated remote attackers to execute code via the administrative API.
