Vulnerabilities > Rasilient

DATE CVE VULNERABILITY TITLE RISK
2020-01-09 CVE-2020-6758 Cross-site Scripting vulnerability in Rasilient Pixelstor 5000 Firmware 4.0.158020150629
A cross-site scripting (XSS) vulnerability in Option/optionsAll.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows remote attackers to inject arbitrary web script or HTML via the ContentFrame parameter.
network
rasilient CWE-79
4.3
2020-01-09 CVE-2020-6757 Improper Input Validation vulnerability in Rasilient Pixelstor 5000 Firmware 4.0.158020150629
contentHostProperties.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows authenticated attackers to remotely execute code via the name parameter.
network
low complexity
rasilient CWE-20
6.5
2020-01-09 CVE-2020-6756 Improper Input Validation vulnerability in Rasilient Pixelstor 5000 Firmware 4.0.158020150629
languageOptions.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows unauthenticated attackers to remotely execute code via the lang parameter.
network
low complexity
rasilient CWE-20
7.5