Total
26 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-12309 | 1 Asustor | 2 As602t, Data Master | 2023-12-10 | 5.0 MEDIUM | 7.5 HIGH |
Directory Traversal in upload.cgi in ASUSTOR ADM version 3.1.1 allows attackers to upload files to arbitrary locations by modifying the "path" URL parameter. NOTE: the "filename" POST parameter is covered by CVE-2018-11345. | |||||
CVE-2018-12315 | 1 Asustor | 2 As602t, Data Master | 2023-12-10 | 4.0 MEDIUM | 6.5 MEDIUM |
Missing verification of a password in ASUSTOR ADM version 3.1.1 allows attackers to change account passwords without entering the current password. | |||||
CVE-2018-12316 | 1 Asustor | 2 As602t, Data Master | 2023-12-10 | 9.0 HIGH | 8.8 HIGH |
OS Command Injection in upload.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands by modifying the filename POST parameter. | |||||
CVE-2018-12318 | 1 Asustor | 2 As602t, Data Master | 2023-12-10 | 4.0 MEDIUM | 8.8 HIGH |
Information disclosure in the SNMP settings page in ASUSTOR ADM version 3.1.1 allows attackers to obtain the SNMP password in cleartext. | |||||
CVE-2018-12305 | 1 Asustor | 1 Data Master | 2023-12-10 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting in File Explorer in ASUSTOR ADM version 3.1.1 allows attackers to execute JavaScript by uploading SVG images with embedded JavaScript. | |||||
CVE-2018-12311 | 1 Asustor | 2 As602t, Data Master | 2023-12-10 | 3.5 LOW | 5.4 MEDIUM |
Cross-site scripting vulnerability in File Explorer in ASUSTOR ADM version 3.1.1 allows attackers to execute arbitrary JavaScript when a file is moved via a malicious filename. |