Vulnerabilities > Direct Request ('Forced Browsing')

DATE CVE VULNERABILITY TITLE RISK
2019-08-06 CVE-2019-14347 Forced Browsing vulnerability in Schben Adive
Internal/Views/addUsers.php in Schben Adive 2.0.7 allows remote unprivileged users (editor or developer) to create an administrator account via admin/user/add, as demonstrated by a Python PoC script.
network
low complexity
schben CWE-425
8.8
2019-07-25 CVE-2019-9884 Forced Browsing vulnerability in Eclass IP 2.5
eClass platform < ip.2.5.10.2.1 allows an attacker to use GETS method to request /admin page to bypass the password validation and access management page.
network
low complexity
eclass CWE-425
critical
9.8
2019-07-19 CVE-2019-13981 Forced Browsing vulnerability in Rangerstudio Directus 7 API
In Directus 7 API through 2.3.0, remote attackers can read image files via a direct request for a filename under the uploads/_/originals/ directory.
network
low complexity
rangerstudio CWE-425
5.3
2019-06-27 CVE-2019-12583 Forced Browsing vulnerability in Zyxel products
Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest accounts by directly accessing the account generator.
network
low complexity
zyxel CWE-425
critical
9.1
2019-06-20 CVE-2019-1899 Forced Browsing vulnerability in Cisco Rv110W Firmware, Rv130W Firmware and Rv215W Firmware
A vulnerability in the web interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to acquire the list of devices that are connected to the guest network.
network
low complexity
cisco CWE-425
5.3
2019-06-20 CVE-2019-1898 Forced Browsing vulnerability in Cisco Rv110W Firmware, Rv130W Firmware and Rv215W Firmware
A vulnerability in the web-based management interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to access the syslog file on an affected device.
network
low complexity
cisco CWE-425
5.3
2019-04-30 CVE-2019-3934 Forced Browsing vulnerability in Crestron Am-100 Firmware and Am-101 Firmware
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to bypass the presentation code sending a crafted HTTP POST request to login.cgi.
network
low complexity
crestron CWE-425
5.3
2019-04-30 CVE-2019-3933 Forced Browsing vulnerability in Crestron Am-100 Firmware and Am-101 Firmware
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to bypass the presentation code simply by requesting /images/browserslide.jpg via HTTP.
network
low complexity
crestron CWE-425
5.3
2019-04-11 CVE-2019-3916 Forced Browsing vulnerability in Verizon Fios Quantum Gateway G1100 Firmware 02.01.00.05
Information disclosure vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows an remote, unauthenticated attacker to retrieve the value of the password salt by simply requesting an API URL in a web browser (e.g.
network
low complexity
verizon CWE-425
7.5
2019-03-21 CVE-2018-18862 Forced Browsing vulnerability in BMC Remedy Action Request System and Remedy Mid-Tier
BMC Remedy Mid-Tier 7.1.00 and 9.1.02.003 for BMC Remedy AR System has Incorrect Access Control in ITAM forms, as demonstrated by TLS%3APLR-Configuration+Details/Default+Admin+View/, AST%3AARServerConnection/Default+Admin+View/, and AR+System+Administration%3A+Server+Information/Default+Admin+View/.
network
low complexity
bmc CWE-425
8.8