
CVE-2020-10671 – Oce Colorwave 500 CSRF / XSS / Authentication Bypass
https://notcve.org/view.php?id=CVE-2020-10671
19 Mar 2020 — The Canon Oce Colorwave 500 4.0.0.0 printer's web application is missing any form of CSRF protections. This is a system-wide issue. An attacker could perform administrative actions by targeting a logged-in administrative user. NOTE: this is fixed in the latest version. La aplicación web de la impresora Canon Oce Colorwave 500 versión 4.0.0.0, no presenta ninguna forma de protecciones de CSRF. • http://packetstormsecurity.com/files/156833/Oce-Colorwave-500-CSRF-XSS-Authentication-Bypass.html • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2020-10667 – Oce Colorwave 500 CSRF / XSS / Authentication Bypass
https://notcve.org/view.php?id=CVE-2020-10667
19 Mar 2020 — The web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to Stored XSS in /TemplateManager/indexExternalLocation.jsp. The vulnerable parameter is map(template_name). NOTE: this is fixed in the latest version. La aplicación web expuesta por la impresora Canon Oce Colorwave 500 versión 4.0.0.0, vulnerable a un ataque de tipo XSS Almacenado en el archivo /TemplateManager/indexExternalLocation.jsp. El parámetro vulnerable es map(template_name). • http://packetstormsecurity.com/files/156833/Oce-Colorwave-500-CSRF-XSS-Authentication-Bypass.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2020-10668 – Oce Colorwave 500 CSRF / XSS / Authentication Bypass
https://notcve.org/view.php?id=CVE-2020-10668
19 Mar 2020 — The web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to Reflected XSS in /home.jsp. The vulnerable parameter is openSI. NOTE: this is fixed in the latest version. La aplicación web expuesta por la impresora Canon Oce Colorwave 500 versión 4.0.0.0, es vulnerable a un ataque de tipo XSS Reflejado en el archivo /home.jsp. El parámetro vulnerable es openSI. • http://packetstormsecurity.com/files/156833/Oce-Colorwave-500-CSRF-XSS-Authentication-Bypass.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2020-10670 – Oce Colorwave 500 CSRF / XSS / Authentication Bypass
https://notcve.org/view.php?id=CVE-2020-10670
19 Mar 2020 — The web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to Reflected XSS in the parameter settingId of the settingDialogContent.jsp page. NOTE: this is fixed in the latest version. La aplicación web expuesta por la impresora Canon Oce Colorwave 500 versión 4.0.0.0, es vulnerable a un ataque de tipo XSS Reflejado en el parámetro settingId de la página settingDialogContent.jsp. NOTA: esto es corregido en la última versión. Oce Colorwave 500 printer suffers from authentication ... • http://packetstormsecurity.com/files/156833/Oce-Colorwave-500-CSRF-XSS-Authentication-Bypass.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2020-10669 – Oce Colorwave 500 CSRF / XSS / Authentication Bypass
https://notcve.org/view.php?id=CVE-2020-10669
19 Mar 2020 — The web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to authentication bypass on the page /home.jsp. An unauthenticated attacker able to connect to the device's web interface can get a copy of the documents uploaded by any users. NOTE: this is fixed in the latest version. La aplicación web expuesta por la impresora Canon Oce Colorwave 500 versión 4.0.0.0, es vulnerable a una omisión de autenticación en la página /home.jsp. Un atacante no autenticado capaz de conectarse a ... • http://packetstormsecurity.com/files/156833/Oce-Colorwave-500-CSRF-XSS-Authentication-Bypass.html • CWE-287: Improper Authentication •