CVE-2021-35491
- EPSS 0.2%
- Veröffentlicht 05.10.2021 16:15:07
- Zuletzt bearbeitet 21.11.2024 06:12:22
A Cross-Site Request Forgery (CSRF) vulnerability in Wowza Streaming Engine through 4.8.11+5 allows a remote attacker to delete a user account via the /enginemanager/server/user/delete.htm userName parameter. The application does not implement a CSRF...
CVE-2021-31539
- EPSS 0.03%
- Veröffentlicht 23.04.2021 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:05:52
Wowza Streaming Engine before 4.8.8.01 (in a default installation) has cleartext passwords stored in the conf/admin.password file. A regular local user is able to read usernames and passwords.
CVE-2021-31540
- EPSS 0.04%
- Veröffentlicht 23.04.2021 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:05:52
Wowza Streaming Engine through 4.8.5 (in a default installation) has incorrect file permissions of configuration files in the conf/ directory. A regular local user is able to read and write to all the configuration files, e.g., modify the application...
CVE-2019-19455
- EPSS 0.03%
- Veröffentlicht 03.08.2020 14:15:15
- Zuletzt bearbeitet 21.11.2024 04:34:46
Wowza Streaming Engine before 4.8.5 has Insecure Permissions which may allow a local attacker to escalate privileges in / usr / local / WowzaStreamingEngine / manager / bin / in the Linux version of the server by writing arbitrary commands in any fil...
CVE-2019-19453
- EPSS 0.44%
- Veröffentlicht 03.08.2020 14:15:15
- Zuletzt bearbeitet 21.11.2024 04:34:45
Wowza Streaming Engine before 4.8.5 allows XSS (issue 1 of 2). An authenticated user, with access to the proxy license editing is able to insert a malicious payload that will be triggered in the main page of server settings. This issue was resolved i...
CVE-2019-19456
- EPSS 0.26%
- Veröffentlicht 18.05.2020 17:15:10
- Zuletzt bearbeitet 21.11.2024 04:34:46
A Reflected XSS was found in the server selection box inside the login page at: enginemanager/loginfailed.html in Wowza Streaming Engine <= 4.x.x. This issue was resolved in Wowza Streaming Engine 4.8.0.
CVE-2019-19454
- EPSS 0.73%
- Veröffentlicht 18.05.2020 17:15:10
- Zuletzt bearbeitet 21.11.2024 04:34:46
An arbitrary file download was found in the "Download Log" functionality of Wowza Streaming Engine <= 4.x.x. This issue was resolved in Wowza Streaming Engine 4.8.0.
- EPSS 0.54%
- Veröffentlicht 14.04.2020 15:15:13
- Zuletzt bearbeitet 21.11.2024 05:39:48
A remote authenticated authorization-bypass vulnerability in Wowza Streaming Engine 4.8.0 and earlier allows any read-only user to issue requests to the administration panel in order to change functionality. For example, a read-only user may activate...
CVE-2019-7656
- EPSS 0.09%
- Veröffentlicht 29.01.2020 16:15:11
- Zuletzt bearbeitet 21.11.2024 04:48:28
A privilege escalation vulnerability in Wowza Streaming Engine 4.8.0 and earlier allows any unprivileged Linux user to escalate privileges to root. The installer sets too relaxed permissions on /usr/local/WowzaStreamingEngine/bin/* core program files...
CVE-2019-7655
- EPSS 0.65%
- Veröffentlicht 29.01.2020 16:15:11
- Zuletzt bearbeitet 21.11.2024 04:48:28
Wowza Streaming Engine 4.8.0 and earlier from multiple authenticated XSS vulnerabilities via the (1) customList%5B0%5D.value field in enginemanager/server/serversetup/edit_adv.htm of the Server Setup configuration or the (2) host field in enginemanag...