9 results (0.006 seconds)

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 0

CSRF vulnerability in Smoothwall Express 3. Una vulnerabilidad de tipo CSRF en Smoothwall Express versión 3. • https://www.openwall.com/lists/oss-security/2011/03/03/7 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

A cross-site scripting (XSS) vulnerability in Smoothwall Express 3. Una vulnerabilidad de tipo cross-site scripting (XSS) en Smoothwall Express versión 3. • https://www.openwall.com/lists/oss-security/2011/03/03/7 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.8EPSS: 0%CPEs: 2EXPL: 3

Cross-site request forgery (CSRF) vulnerability in the web management interface in httpd/cgi-bin/shutdown.cgi in Smoothwall Express 3.1 and 3.0 SP3 and earlier allows remote attackers to hijack the authentication of administrators for requests that perform a reboot via a request to cgi-bin/shutdown.cgi. Vulnerabilidad de CSRF en la interfaz de gestión web en httpd/cgi-bin/shutdown.cgi en Smoothwall Express 3.1 y 3.0 SP3 y anteriores permite a atacantes remotos secuestrar la autenticación de administradores para solicitudes que realizan un reinicio a través de una solicitud a cgi-bin/shutdown.cgi. • https://www.exploit-db.com/exploits/16006 http://osvdb.org/show/osvdb/70497 http://packetstormsecurity.com/files/129698/SmoothWall-3.1-Cross-Site-Request-Forgery-Cross-Site-Scripting.html http://www.exploit-db.com/exploits/16006 https://exchange.xforce.ibmcloud.com/vulnerabilities/99403 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 4.3EPSS: 0%CPEs: 2EXPL: 3

Cross-site scripting (XSS) vulnerability in the web management interface in httpd/cgi-bin/ipinfo.cgi in Smoothwall Express 3.1 and 3.0 SP3 and earlier allows remote attackers to inject arbitrary web script or HTML via the IP parameter in a Run action. Vulnerabilidad de XSS en la interfaz de gestión de web en httpd/cgi-bin/ipinfo.cgi en Smoothwall Express 3.1 y 3.0 SP3 y anteriores permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través del parámetro IP en una acción Run. • https://www.exploit-db.com/exploits/16006 http://osvdb.org/show/osvdb/70496 http://packetstormsecurity.com/files/129698/SmoothWall-3.1-Cross-Site-Request-Forgery-Cross-Site-Scripting.html http://www.exploit-db.com/exploits/16006 https://exchange.xforce.ibmcloud.com/vulnerabilities/99404 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 1

Cross-site scripting (XSS) vulnerability in httpd/cgi-bin/vpn.cgi/vpnconfig.dat in Smoothwall Express 3.0 SP3 allows remote attackers to inject arbitrary web script or HTML via the COMMENT parameter in an Add action. Vulnerabilidad de XSS en httpd/cgi-bin/vpn.cgi/vpnconfig.dat en Smoothwall Express 3.0 SP3 permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través del parámetro COMMENT en una acción Add. • http://packetstormsecurity.com/files/129698/SmoothWall-3.1-Cross-Site-Request-Forgery-Cross-Site-Scripting.html https://exchange.xforce.ibmcloud.com/vulnerabilities/99404 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •