Search: "sonicwall"

143 CVEs found

CVE-2012-3848
4.3 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 allow remote attackers to inject arbitrary web script or HTML...

Published: 2012-07-31
Products: 1
Vendors:
sonicwall

The MySQL component in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) 9.0.1.19899 and earlier has a default password of admin for the (1) scrutinizer and (2) scrutremote accounts, which allows re...

Published: 2012-07-31
Products: 1
Vendors:
sonicwall

SQL injection vulnerability in sgms/reports/scheduledreports/configure/scheduleProps.jsp in SonicWall ViewPoint 6.0 SP2 allows remote attackers to execute arbitrary SQL commands via the scheduleID par...

Published: 2012-09-15
Products: 1
Vendors:
dell

SQL injection vulnerability in prodpage.cfm in SonicWALL Aventail allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter.

Published: 2013-02-12
Products: 4
Vendors:
sonicwall

Multiple cross-site scripting (XSS) vulnerabilities in ematStaticAlertTypes.jsp in the Alert Settings section in Dell SonicWALL Global Management System (GMS), Analyzer, and UMA EM5000 7.1 SP1 before ...

Published: 2013-12-09
Products: 10
Vendors:
sonicwall
CVE-2014-0332
4.3 MEDIUM

Cross-site scripting (XSS) vulnerability in mainPage in Dell SonicWALL GMS before 7.1 SP2, SonicWALL Analyzer before 7.1 SP2, and SonicWALL UMA E5000 before 7.1 SP2 might allow remote attackers to inj...

Published: 2014-02-14
Products: 10
Vendors:
sonicwall
CVE-2014-2589
4.3 MEDIUM

Cross-site scripting (XSS) vulnerability in the Dashboard Backend service (stats/dashboard.jsp) in SonicWall Network Security Appliance (NSA) 2400 allows remote attackers to inject arbitrary web scrip...

Published: 2014-03-24
Products: 1
Vendors:
sonicwall
CVE-2014-2879
4.3 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in Dell SonicWALL Email Security 7.4.5 and earlier allow remote authenticated administrators to inject arbitrary web script or HTML via (1) the uplo...

Published: 2014-04-17
Products: 1
Vendors:
sonicwall
CVE-2014-4976
5.5 MEDIUM

Dell SonicWall Scrutinizer 11.0.1 allows remote authenticated users to change user passwords via the user ID in the savePrefs parameter in a change password request to cgi-bin/admin.cgi.

Published: 2014-07-16
Products: 1
Vendors:
sonicwall
CVE-2014-4977
6.5 MEDIUM

Multiple SQL injection vulnerabilities in Dell SonicWall Scrutinizer 11.0.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) selectedUserGroup parameter in a create new u...

Published: 2014-07-16
Products: 1
Vendors:
sonicwall
CVE-2014-5024
4.3 MEDIUM

Cross-site scripting (XSS) vulnerability in sgms/panelManager in Dell SonicWALL GMS, Analyzer, and UMA before 7.2 SP1 allows remote attackers to inject arbitrary web script or HTML via the node_id par...

Published: 2014-07-24
Products: 3
Vendors:
sonicwall

The ViewPoint web application in Dell SonicWALL Global Management System (GMS) before 7.2 SP2, SonicWALL Analyzer before 7.2 SP2, and SonicWALL UMA before 7.2 SP2 allows remote authenticated users to ...

Published: 2014-11-25
Products: 3
Vendors:
sonicwall
CVE-2015-3447
4.3 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in macIpSpoofView.html in Dell SonicWall SonicOS 7.5.0.12 and 6.x allow remote attackers to inject arbitrary web script or HTML via the (1) searchSp...

Published: 2015-04-29
Products: 2
Vendors:
sonicwall
CVE-2015-2248
6.8 MEDIUM

Cross-site request forgery (CSRF) vulnerability in the user portal in Dell SonicWALL Secure Remote Access (SRA) products with firmware before 7.5.1.0-38sv and 8.x before 8.0.0.1-16sv allows remote att...

Published: 2015-05-01
Products: 2
Vendors:
sonicwall

The GMS ViewPoint (GMSVP) web application in Dell Sonicwall GMS, Analyzer, and UMA EM5000 before 7.2 SP4 allows remote authenticated users to execute arbitrary commands via vectors related to configur...

Published: 2015-05-20
Products: 4
Vendors:
sonicwall
CVE-2015-4173
6.9 MEDIUM

Unquoted Windows search path vulnerability in the autorun value in Dell SonicWall NetExtender before 7.5.227 and 8.0.x before 8.0.238, as used in the SRA firmware before 7.5.1.2-40sv and 8.x before 8....

Published: 2015-08-26
Products: 2
Vendors:
sonicwall
CVE-2015-7770
5.0 MEDIUM

Dell SonicWall TotalSecure TZ 100 devices with firmware before 5.9.1.0-22o allow remote attackers to cause a denial of service via a crafted packet.

Published: 2015-11-06
Products: 1
Vendors:
dell
CVE-2016-2396
9.9 CRITICAL

The GMS ViewPoint (GMSVP) web application in Dell SonicWALL GMS, Analyzer, and UMA EM5000 7.2, 8.0, and 8.1 before Hotfix 168056 allows remote authenticated users to execute arbitrary commands via vec...

Published: 2016-02-17
Products: 10
Vendors:
sonicwall
CVE-2016-2397
9.8 CRITICAL

The cliserver implementation in Dell SonicWALL GMS, Analyzer, and UMA EM5000 7.2, 8.0, and 8.1 before Hotfix 168056 allows remote attackers to deserialize and execute arbitrary Java code via crafted X...

Published: 2016-02-17
Products: 10
Vendors:
sonicwall
CVE-2016-9682
9.8 CRITICAL

The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to two Remote Command Injection vulnerabilities in its web administrative interface. These vulnerabilities occur in the d...

Published: 2017-02-22
Products: 1
Vendors:
dell