CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
104008 | CVE-2017-7188 | Candidate | Zurmo 3.1.1 Stable allows a Cross-Site Scripting (XSS) attack with a base64-encoded SCRIPT element within a data: URL in the returnUrl parameter to default/toggleCollapse. | Assigned (20170320) | None (candidate not yet proposed) | View | |
71450 | CVE-2014-4154 | Candidate | ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the PPPoE/PPPoA password via a direct request for basic/tc2wanfun.js. | Assigned (20140612) | None (candidate not yet proposed) | View | |
84528 | CVE-2015-7251 | Candidate | ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE have a hardcoded password of root for the root account, which allows remote attackers to obtain administrative access via a TELNET session. | Assigned (20150918) | None (candidate not yet proposed) | View | |
85980 | CVE-2015-8703 | Candidate | ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE and ZXV10 W300 devices W300V1.0.0f_ER1_PE allow remote authenticated users to bypass intended access restrictions, and discover credentials and keys, by reading the configuration file, a different vulnerability than CVE-2015-7248. | Assigned (20151229) | None (candidate not yet proposed) | View | |
84526 | CVE-2015-7249 | Candidate | ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allow remote authenticated users to bypass intended access restrictions via a modified request, as demonstrated by leveraging the support account to change a password via a cgi-bin/webproc accountpsd action. | Assigned (20150918) | None (candidate not yet proposed) | View |
Page 8 of 20943, showing 5 records out of 104715 total, starting on record 36, ending on 40