Wowza

Streaming Engine

26 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.2%
  • Veröffentlicht 05.10.2021 16:15:07
  • Zuletzt bearbeitet 21.11.2024 06:12:22

A Cross-Site Request Forgery (CSRF) vulnerability in Wowza Streaming Engine through 4.8.11+5 allows a remote attacker to delete a user account via the /enginemanager/server/user/delete.htm userName parameter. The application does not implement a CSRF...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 23.04.2021 17:15:08
  • Zuletzt bearbeitet 21.11.2024 06:05:52

Wowza Streaming Engine before 4.8.8.01 (in a default installation) has cleartext passwords stored in the conf/admin.password file. A regular local user is able to read usernames and passwords.

Exploit
  • EPSS 0.04%
  • Veröffentlicht 23.04.2021 17:15:08
  • Zuletzt bearbeitet 21.11.2024 06:05:52

Wowza Streaming Engine through 4.8.5 (in a default installation) has incorrect file permissions of configuration files in the conf/ directory. A regular local user is able to read and write to all the configuration files, e.g., modify the application...

  • EPSS 0.03%
  • Veröffentlicht 03.08.2020 14:15:15
  • Zuletzt bearbeitet 21.11.2024 04:34:46

Wowza Streaming Engine before 4.8.5 has Insecure Permissions which may allow a local attacker to escalate privileges in / usr / local / WowzaStreamingEngine / manager / bin / in the Linux version of the server by writing arbitrary commands in any fil...

  • EPSS 0.44%
  • Veröffentlicht 03.08.2020 14:15:15
  • Zuletzt bearbeitet 21.11.2024 04:34:45

Wowza Streaming Engine before 4.8.5 allows XSS (issue 1 of 2). An authenticated user, with access to the proxy license editing is able to insert a malicious payload that will be triggered in the main page of server settings. This issue was resolved i...

  • EPSS 0.26%
  • Veröffentlicht 18.05.2020 17:15:10
  • Zuletzt bearbeitet 21.11.2024 04:34:46

A Reflected XSS was found in the server selection box inside the login page at: enginemanager/loginfailed.html in Wowza Streaming Engine <= 4.x.x. This issue was resolved in Wowza Streaming Engine 4.8.0.

  • EPSS 0.73%
  • Veröffentlicht 18.05.2020 17:15:10
  • Zuletzt bearbeitet 21.11.2024 04:34:46

An arbitrary file download was found in the "Download Log" functionality of Wowza Streaming Engine <= 4.x.x. This issue was resolved in Wowza Streaming Engine 4.8.0.

Exploit
  • EPSS 0.54%
  • Veröffentlicht 14.04.2020 15:15:13
  • Zuletzt bearbeitet 21.11.2024 05:39:48

A remote authenticated authorization-bypass vulnerability in Wowza Streaming Engine 4.8.0 and earlier allows any read-only user to issue requests to the administration panel in order to change functionality. For example, a read-only user may activate...

Exploit
  • EPSS 0.09%
  • Veröffentlicht 29.01.2020 16:15:11
  • Zuletzt bearbeitet 21.11.2024 04:48:28

A privilege escalation vulnerability in Wowza Streaming Engine 4.8.0 and earlier allows any unprivileged Linux user to escalate privileges to root. The installer sets too relaxed permissions on /usr/local/WowzaStreamingEngine/bin/* core program files...

Exploit
  • EPSS 0.65%
  • Veröffentlicht 29.01.2020 16:15:11
  • Zuletzt bearbeitet 21.11.2024 04:48:28

Wowza Streaming Engine 4.8.0 and earlier from multiple authenticated XSS vulnerabilities via the (1) customList%5B0%5D.value field in enginemanager/server/serversetup/edit_adv.htm of the Server Setup configuration or the (2) host field in enginemanag...