Vulnerabilities > Netgate
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-02-20 | CVE-2019-8953 | Cross-site Scripting vulnerability in Netgate Haproxy The HAProxy package before 0.59_16 for pfSense has XSS via the desc (aka Description) or table_actionsaclN parameter, related to haproxy_listeners.php and haproxy_listeners_edit.php. | 6.1 |
2018-12-03 | CVE-2018-4021 | OS Command Injection vulnerability in Netgate Pfsense 2.4.4 An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request. | 7.2 |
2018-12-03 | CVE-2018-4020 | OS Command Injection vulnerability in Netgate Pfsense 2.4.4 An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request. | 7.2 |
2018-12-03 | CVE-2018-4019 | OS Command Injection vulnerability in Netgate Pfsense 2.4.4 An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request. | 7.2 |
2018-09-26 | CVE-2018-16055 | OS Command Injection vulnerability in Netgate Pfsense An authenticated command injection vulnerability exists in status_interfaces.php via dhcp_relinquish_lease() in pfSense before 2.4.4 due to its passing user input from the $_POST parameters "ifdescr" and "ipv" to a shell without escaping the contents of the variables. | 8.8 |
2018-01-03 | CVE-2017-1000479 | Cross-Site Request Forgery (CSRF) vulnerability in multiple products pfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the CSRF error page resulting in privileged execution of arbitrary code, because the error detection occurs before an X-Frame-Options header is set. | 8.8 |