Vulnerabilities > Direct Request ('Forced Browsing')

DATE CVE VULNERABILITY TITLE RISK
2019-06-20 CVE-2019-1898 Forced Browsing vulnerability in Cisco Rv110W Firmware, Rv130W Firmware and Rv215W Firmware
A vulnerability in the web-based management interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to access the syslog file on an affected device.
network
low complexity
cisco CWE-425
5.3
2019-04-30 CVE-2019-3934 Forced Browsing vulnerability in Crestron Am-100 Firmware and Am-101 Firmware
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to bypass the presentation code sending a crafted HTTP POST request to login.cgi.
network
low complexity
crestron CWE-425
5.3
2019-04-30 CVE-2019-3933 Forced Browsing vulnerability in Crestron Am-100 Firmware and Am-101 Firmware
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to bypass the presentation code simply by requesting /images/browserslide.jpg via HTTP.
network
low complexity
crestron CWE-425
5.3
2019-04-11 CVE-2019-3916 Forced Browsing vulnerability in Verizon Fios Quantum Gateway G1100 Firmware 02.01.00.05
Information disclosure vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows an remote, unauthenticated attacker to retrieve the value of the password salt by simply requesting an API URL in a web browser (e.g.
network
low complexity
verizon CWE-425
7.5
2019-03-21 CVE-2018-18862 Forced Browsing vulnerability in BMC Remedy Action Request System and Remedy Mid-Tier
BMC Remedy Mid-Tier 7.1.00 and 9.1.02.003 for BMC Remedy AR System has Incorrect Access Control in ITAM forms, as demonstrated by TLS%3APLR-Configuration+Details/Default+Admin+View/, AST%3AARServerConnection/Default+Admin+View/, and AR+System+Administration%3A+Server+Information/Default+Admin+View/.
network
low complexity
bmc CWE-425
8.8
2019-03-05 CVE-2019-3917 Forced Browsing vulnerability in Nokia I-240W-Q Gpon ONT Firmware 3Fe54567Bozj19
The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 allows a remote, unauthenticated attacker to enable telnetd on the router via a crafted HTTP request.
network
low complexity
nokia CWE-425
7.5
2019-03-04 CVE-2019-9552 Forced Browsing vulnerability in Eloan Project Eloan 20180920/3.0
Eloan V3.0 through 2018-09-20 allows remote attackers to list files via a direct request to the p2p/api/ or p2p/lib/ or p2p/images/ URI.
network
low complexity
eloan-project CWE-425
critical
9.8
2019-02-28 CVE-2019-6551 Forced Browsing vulnerability in Pangea-Comm FAX ATA 3.1.8
Pangea Communications Internet FAX ATA all Versions 3.1.8 and prior allow an attacker to bypass user authentication using a specially crafted URL to cause the device to reboot, which may be used to cause a continual denial-of-service condition.
network
low complexity
pangea-comm CWE-425
7.5
2019-02-11 CVE-2019-7736 Forced Browsing vulnerability in Dlink Dir-600M Firmware 3.04
D-Link DIR-600M C1 3.04 devices allow authentication bypass via a direct request to the wan.htm page.
network
low complexity
dlink CWE-425
critical
9.8
2019-01-11 CVE-2019-6126 Forced Browsing vulnerability in Advance Peer to Peer MLM Script Project Advance Peer to Peer MLM Script 1.7.0
The Admin Panel of PHP Scripts Mall Advance Peer to Peer MLM Script v1.7.0 allows remote attackers to bypass intended access restrictions by directly navigating to admin/dashboard.php or admin/user.php, as demonstrated by disclosure of information about users and staff.
7.5