CVE-2018-14704
- EPSS 0.24%
- Veröffentlicht 03.12.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 03:49:37
Cross-site scripting in the MySQL API error page in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execute JavaScript via a malformed URL path.
- EPSS 63.86%
- Veröffentlicht 03.12.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 03:49:37
System command injection in the /DroboPix/api/drobopix/demo endpoint on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to execute system commands via the payload in a POST request.
CVE-2018-14707
- EPSS 2.78%
- Veröffentlicht 03.12.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 03:49:37
Directory traversal in the Drobo Pix web application on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to upload files to arbitrary locations.
CVE-2018-14708
- EPSS 0.48%
- Veröffentlicht 03.12.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 03:49:38
An insecure transport protocol used by Drobo Dashboard API on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to intercept network traffic.
CVE-2018-14709
- EPSS 0.62%
- Veröffentlicht 03.12.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 03:49:38
Incorrect access control in the Dashboard API on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to bypass authentication due to insecure token generation.