Vulnerabilities > Seagate > NAS OS

DATE CVE VULNERABILITY TITLE RISK
2019-05-13 CVE-2018-12304 Cross-site Scripting vulnerability in Seagate NAS OS 4.3.15.1
Cross-site scripting in Application Manager in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via multiple application metadata fields: Short Description, Publisher Name, Publisher Contact, or Website URL.
network
low complexity
seagate CWE-79
6.1
2019-05-13 CVE-2018-12303 Cross-site Scripting vulnerability in Seagate NAS OS 4.3.15.1
Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via directory names.
network
low complexity
seagate CWE-79
5.4
2019-05-13 CVE-2018-12302 Cross-site Scripting vulnerability in Seagate NAS OS 4.3.15.1
Missing HTTPOnly flag on session cookies in the Seagate NAS OS version 4.3.15.1 web application allows attackers to steal session tokens via cross-site scripting.
network
low complexity
seagate CWE-79
6.1
2019-05-13 CVE-2018-12301 Information Exposure vulnerability in Seagate NAS OS 4.3.15.1
Unvalidated URL in Download Manager in Seagate NAS OS version 4.3.15.1 allows attackers to access the loopback interface via a Download URL of 127.0.0.1 or localhost.
network
low complexity
seagate CWE-200
7.5
2019-05-13 CVE-2018-12300 Open Redirect vulnerability in Seagate NAS OS 4.3.15.1
Arbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclose information in the Referer header via the 'state' URL parameter.
network
low complexity
seagate CWE-601
6.1
2019-05-13 CVE-2018-12299 Cross-site Scripting vulnerability in Seagate NAS OS 4.3.15.1
Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via uploaded file names.
network
low complexity
seagate CWE-79
5.4
2019-05-13 CVE-2018-12298 Path Traversal vulnerability in Seagate NAS OS 4.3.15.1
Directory Traversal in filebrowser in Seagate NAS OS 4.3.15.1 allows attackers to read files within the application's container via a URL path.
network
low complexity
seagate CWE-22
7.5
2019-05-13 CVE-2018-12297 Cross-site Scripting vulnerability in Seagate NAS OS 4.3.15.1
Cross-site scripting in API error pages in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via URL path names.
network
low complexity
seagate CWE-79
6.1
2019-05-13 CVE-2018-12296 Incorrect Permission Assignment for Critical Resource vulnerability in Seagate NAS OS 4.3.15.1
Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attackers to obtain information about the NAS without authentication via empty POST requests.
network
low complexity
seagate CWE-732
7.5
2019-05-13 CVE-2018-12295 SQL Injection vulnerability in Seagate NAS OS 4.3.15.1
SQL injection in folderViewSpecific.psp in Seagate NAS OS version 4.3.15.1 allows attackers to execute arbitrary SQL commands via the dirId URL parameter.
network
low complexity
seagate CWE-89
critical
9.8