Vulnerabilities > Paloaltonetworks > Expedition > 1.0.106

DATE CVE VULNERABILITY TITLE RISK
2019-03-26 CVE-2019-1571 Cross-site Scripting vulnerability in Paloaltonetworks Expedition
The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the RADIUS server settings.
3.5
2019-03-26 CVE-2019-1570 Cross-site Scripting vulnerability in Paloaltonetworks Expedition
The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the LDAP server settings.
3.5
2019-03-26 CVE-2019-1569 Cross-site Scripting vulnerability in Paloaltonetworks Expedition
The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the User Mapping Settings for account name of admin user.
3.5
2018-11-27 CVE-2018-10142 Information Exposure vulnerability in Paloaltonetworks Expedition 1.0.106
The Expedition Migration tool 1.0.106 and earlier may allow an unauthenticated attacker to enumerate files on the operating system.
network
low complexity
paloaltonetworks CWE-200
5.0