Vulnerabilities
11 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-5407 | A vulnerability in RhinOS 3.0-1190 could allow PHP code injection through the "search" parameter in /portal/search.htm. A vulnerability in RhinOS 3.0-1190 could allow PHP code injection through the "search" parameter in /portal/search.htm. This vulnerability could allow a remote attacker to perform a reverse shell on the remote system, compromising the entire infrastructure. NVD description · AI analysis pending | 9.8 group max | <1% |
| — | ||
| CVE-2019-19459 | An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. An attacker can write arbitrary content to arbitrary files, as demonstrated by CVE-2019-19458 files under the web root, or .bat files that will be used with auto start. This allows an attacker to execute arbitrary commands on the server. NVD description · AI analysis pending | 9.8 group max | 4% | PoC |
| — | |
| CVE-2018-18762 | SaltOS 3.1 r8126 contains a database download vulnerability. SaltOS 3.1 r8126 contains a database download vulnerability. NVD description · AI analysis pending | 6.5 | 6% | PoC ×2 |
| — | |
| CVE-2018-18761 +1 in the same advisory: …18763 | SaltOS 3.1 r8126 allows action=login&querystring=&user=[SQL] SQL Injection. SaltOS 3.1 r8126 allows action=login&querystring=&user=[SQL] SQL Injection. NVD description · AI analysis pending | 9.8 | 16% | PoC |
| — | |
| CVE-2018-18760 | RhinOS 3.0 build 1190 allows CSRF. RhinOS 3.0 build 1190 allows CSRF. NVD description · AI analysis pending | 6.5 | 3% | PoC ×2 |
| — |