Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In 2018
The YunoHost 2.7.2 through 2.7.14 web application is affected by one HTTP Response Header Injection. This flaw allows an attacker to inject, into the response from the server, one or several HTTP Header. It requires an interaction with the user to send him the malicious link. It could be used to perform other attacks such as user redirection to a malicious website, HTTP response splitting, or HTTP cache poisoning.
CVSS Score
8.8
EPSS Score
0.004
Published
2018-12-04
Two XSS vulnerabilities are located in the profile edition page of the user panel of the YunoHost 2.7.2 through 2.7.14 web application. By injecting a JavaScript payload, these flaws could be used to manipulate a user's session.
CVSS Score
5.4
EPSS Score
0.002
Published
2018-12-04
Cross-site scripting in File Explorer in ASUSTOR ADM version 3.1.1 allows attackers to execute JavaScript by uploading SVG images with embedded JavaScript.
CVSS Score
6.1
EPSS Score
0.002
Published
2018-12-04
Directory Traversal in File Explorer in ASUSTOR ADM version 3.1.1 allows attackers to view arbitrary files by modifying the "file1" URL parameter, a similar issue to CVE-2018-11344.
CVSS Score
7.5
EPSS Score
0.006
Published
2018-12-04
OS command injection in user.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root via the "name" POST parameter.
CVSS Score
8.8
EPSS Score
0.12
Published
2018-12-04
Encryption key disclosure in share.cgi in ASUSTOR ADM version 3.1.1 allows attackers to obtain the encryption key via the "encrypt_key" URL parameter.
CVSS Score
6.5
EPSS Score
0.002
Published
2018-12-04
Directory Traversal in upload.cgi in ASUSTOR ADM version 3.1.1 allows attackers to upload files to arbitrary locations by modifying the "path" URL parameter. NOTE: the "filename" POST parameter is covered by CVE-2018-11345.
CVSS Score
7.5
EPSS Score
0.006
Published
2018-12-04
Cross-site scripting in the Login page in ASUSTOR ADM version 3.1.1 allows attackers to execute JavaScript via the System Announcement feature.
CVSS Score
5.4
EPSS Score
0.002
Published
2018-12-04
Cross-site scripting vulnerability in File Explorer in ASUSTOR ADM version 3.1.1 allows attackers to execute arbitrary JavaScript when a file is moved via a malicious filename.
CVSS Score
5.4
EPSS Score
0.002
Published
2018-12-04
OS command injection in user.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root via the "secret_key" URL parameter.
CVSS Score
8.8
EPSS Score
0.12
Published
2018-12-04


Contact Us

Shodan ® - All rights reserved