Vulnerabilities > Rasilient

DATE CVE VULNERABILITY TITLE RISK
2020-01-09 CVE-2020-6758 Cross-site Scripting vulnerability in Rasilient Pixelstor 5000 Firmware 4.0.158020150629
A cross-site scripting (XSS) vulnerability in Option/optionsAll.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows remote attackers to inject arbitrary web script or HTML via the ContentFrame parameter.
network
low complexity
rasilient CWE-79
6.1
2020-01-09 CVE-2020-6757 OS Command Injection vulnerability in Rasilient Pixelstor 5000 Firmware 4.0.158020150629
contentHostProperties.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows authenticated attackers to remotely execute code via the name parameter.
network
low complexity
rasilient CWE-78
8.8
2020-01-09 CVE-2020-6756 OS Command Injection vulnerability in Rasilient Pixelstor 5000 Firmware 4.0.158020150629
languageOptions.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows unauthenticated attackers to remotely execute code via the lang parameter.
network
low complexity
rasilient CWE-78
critical
9.8