Vulnerabilities > Direct Request ('Forced Browsing')

DATE CVE VULNERABILITY TITLE RISK
2018-12-13 CVE-2018-18922 Forced Browsing vulnerability in Abisoftgt Ticketly 1.0
add_user in AbiSoft Ticketly 1.0 allows remote attackers to create administrator accounts via an action/add_user.php POST request.
network
low complexity
abisoftgt CWE-425
critical
9.8
2018-11-28 CVE-2018-19620 Forced Browsing vulnerability in Showdoc 2.4.1
ShowDoc 2.4.1 allows remote attackers to edit other users' notes by navigating with a modified page_id.
network
low complexity
showdoc CWE-425
4.0
2018-11-12 CVE-2018-19207 Forced Browsing vulnerability in Van-Ons Wp-Gdpr-Compliance
The Van Ons WP GDPR Compliance (aka wp-gdpr-compliance) plugin before 1.4.3 for WordPress allows remote attackers to execute arbitrary code because $wpdb->prepare() input is mishandled, as exploited in the wild in November 2018.
network
low complexity
van-ons CWE-425
7.5
2018-11-11 CVE-2018-19143 Forced Browsing vulnerability in multiple products
Open Ticket Request System (OTRS) 4.0.x before 4.0.33, 5.0.x before 5.0.31, and 6.0.x before 6.0.13 allows an authenticated user to delete files via a modified submission form because upload caching is mishandled.
network
low complexity
otrs debian CWE-425
5.5
2018-11-08 CVE-2018-19109 Forced Browsing vulnerability in Tianti Project Tianti 2.3
tianti 2.3 allows remote authenticated users to bypass intended permission restrictions by visiting tianti-module-admin/cms/column/list directly to read the column list page or edit a column.
network
low complexity
tianti-project CWE-425
6.5
2018-09-14 CVE-2018-16706 Forced Browsing vulnerability in LG Supersign CMS
LG SuperSign CMS allows TVs to be rebooted remotely without authentication via a direct HTTP request to /qsr_server/device/reboot on port 9080.
network
low complexity
lg CWE-425
7.8
2018-05-24 CVE-2018-7526 Forced Browsing vulnerability in Beaconmedaes Scroll Medical AIR Systems Firmware
In TotalAlert Web Application in BeaconMedaes Scroll Medical Air Systems prior to v4107600010.23, by accessing a specific uniform resource locator (URL) on the webserver, a malicious user may be able to access information in the application without authenticating.
network
low complexity
beaconmedaes CWE-425
5.0
2018-05-22 CVE-2018-11346 Forced Browsing vulnerability in Asustor As6202T Firmware
An insecure direct object reference vulnerability in download.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows the ability to reference the "download_sys_settings" action and then specify files arbitrarily throughout the system via the act parameter.
network
low complexity
asustor CWE-425
4.0
2018-04-19 CVE-2018-0267 Forced Browsing vulnerability in Cisco Unified Communications Manager
A vulnerability in the web framework of Cisco Unified Communications Manager could allow an authenticated, local attacker to view sensitive data that should be restricted.
local
low complexity
cisco CWE-425
2.1
2018-04-19 CVE-2018-0266 Forced Browsing vulnerability in Cisco Unified Communications Manager
A vulnerability in the web framework of Cisco Unified Communications Manager could allow an authenticated, remote attacker to view sensitive data.
network
low complexity
cisco CWE-425
4.0