Endian

Firewall

36 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.49%
  • Veröffentlicht 02.04.2026 14:45:49
  • Zuletzt bearbeitet 07.04.2026 14:38:25

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_firewall.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, ...

  • EPSS 0.49%
  • Veröffentlicht 02.04.2026 14:45:48
  • Zuletzt bearbeitet 07.04.2026 14:38:50

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_clamav.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, wh...

  • EPSS 0.49%
  • Veröffentlicht 02.04.2026 14:45:48
  • Zuletzt bearbeitet 07.04.2026 14:39:06

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_proxy.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, whi...

  • EPSS 0.16%
  • Veröffentlicht 02.04.2026 14:45:47
  • Zuletzt bearbeitet 07.04.2026 14:42:38

Endian Firewall version 3.3.25 and prior allow authenticated users to delete arbitrary files via directory traversal in the remove ARCHIVE parameter to /cgi-bin/backup.cgi. The remove ARCHIVE parameter value is used to construct a file path without s...

Exploit
  • EPSS 3.19%
  • Veröffentlicht 15.09.2012 17:55:07
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Multiple cross-site scripting (XSS) vulnerabilities in Endian Firewall 2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) createrule parameter to dnat.cgi, (2) addrule parameter to dansguardian.cgi, or (3) PATH_INFO to open...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 30.01.2008 22:00:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Cross-site scripting (XSS) vulnerability in vpnum/userslist.php in Endian Firewall 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the psearch parameter. NOTE: the provenance of this information is unknown; the details are o...