Vulnerabilities > Xinuos

DATE CVE VULNERABILITY TITLE RISK
2020-12-18 CVE-2020-25495 Cross-site Scripting vulnerability in Xinuos Openserver 5.0.7/6.0
A reflected Cross-site scripting (XSS) vulnerability in Xinuo (formerly SCO) Openserver version 5 and 6 allows remote attackers to inject arbitrary web script or HTML tag via the parameter 'section'.
network
xinuos CWE-79
4.3
2020-12-18 CVE-2020-25494 Argument Injection or Modification vulnerability in Xinuos Openserver 5.0.7/6.0
Xinuos (formerly SCO) Openserver v5 and v6 allows attackers to execute arbitrary commands via shell metacharacters in outputform or toclevels parameter to cgi-bin/printbook.
network
low complexity
xinuos CWE-88
7.5
2004-08-18 CVE-2004-0230 TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP.
network
low complexity
oracle openpgp mcafee netbsd xinuos juniper
5.0