Vulnerabilities > Seagate > NAS OS > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-05-13 | CVE-2018-12304 | Cross-site Scripting vulnerability in Seagate NAS OS 4.3.15.1 Cross-site scripting in Application Manager in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via multiple application metadata fields: Short Description, Publisher Name, Publisher Contact, or Website URL. | 6.1 |
2019-05-13 | CVE-2018-12303 | Cross-site Scripting vulnerability in Seagate NAS OS 4.3.15.1 Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via directory names. | 5.4 |
2019-05-13 | CVE-2018-12302 | Cross-site Scripting vulnerability in Seagate NAS OS 4.3.15.1 Missing HTTPOnly flag on session cookies in the Seagate NAS OS version 4.3.15.1 web application allows attackers to steal session tokens via cross-site scripting. | 6.1 |
2019-05-13 | CVE-2018-12300 | Open Redirect vulnerability in Seagate NAS OS 4.3.15.1 Arbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclose information in the Referer header via the 'state' URL parameter. | 6.1 |
2019-05-13 | CVE-2018-12299 | Cross-site Scripting vulnerability in Seagate NAS OS 4.3.15.1 Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via uploaded file names. | 5.4 |
2019-05-13 | CVE-2018-12297 | Cross-site Scripting vulnerability in Seagate NAS OS 4.3.15.1 Cross-site scripting in API error pages in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via URL path names. | 6.1 |