Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
terra-master tos vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2018-13360
Cross-site scripting in Text Editor in TerraMaster TOS version 3.1.03 allows malicious users to execute JavaScript via the "filename" URL parameter.
Terra-master Terramaster Operating System 3.1.03
4.3
CVSSv2
CVE-2018-13349
Cross-site scripting in the web application taskbar in TerraMaster TOS version 3.1.03 allows malicious users to execute JavaScript via the user's username.
Terra-master Terramaster Operating System 3.1.03
4.3
CVSSv2
CVE-2018-13329
Cross-site scripting in ajaxdata.php in TerraMaster TOS version 3.1.03 allows malicious users to execute JavaScript via the "lines" URL parameter.
Terra-master Terramaster Operating System 3.1.03
4.3
CVSSv2
CVE-2018-13334
Cross-site scripting in handle.php in TerraMaster TOS version 3.1.03 allows malicious users to execute JavaScript via the "options[sysname]" parameter.
Terra-master Terramaster Operating System 3.1.03
4
CVSSv2
CVE-2021-45839
It is possible to obtain the first administrator's hash set up on the system in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) as well as other information such as MAC address, internal IP address etc. by performing a request to the /module/api.php?mobile/webNasIPS...
Terra-master Tos 4.2.15-2107141517
1 Metasploit module
4
CVSSv2
CVE-2018-13355
Incorrect access controls in ajaxdata.php in TerraMaster TOS version 3.1.03 allow malicious users to create user groups without proper authorization.
Terra-master Terramaster Operating System 3.1.03
3.5
CVSSv2
CVE-2020-28184
Cross-site scripting (XSS) vulnerability in TerraMaster TOS <= 4.2.06 allows remote authenticated users to inject arbitrary web script or HTML via the mod parameter to /module/index.php.
Terra-master Tos
3.5
CVSSv2
CVE-2018-13335
Cross-site scripting in Control Panel in TerraMaster TOS version 3.1.03 allows malicious users to execute JavaScript when viewing shared folders via their descriptions.
Terra-master Terramaster Operating System 3.1.03
3.5
CVSSv2
CVE-2018-13351
Cross-site scripting in Control Panel in TerraMaster TOS version 3.1.03 allows malicious users to execute JavaScript via the edit password form.
Terra-master Terramaster Operating System 3.1.03
3.5
CVSSv2
CVE-2018-13357
Cross-site scripting in Control Panel in TerraMaster TOS version 3.1.03 allows malicious users to execute JavaScript when viewing Shared Folders via JavaScript in Shared Folders' names.
Terra-master Terramaster Operating System 3.1.03
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
buffer overflow
type confusion
server-side request forgery
CVE-2024-38440
CVE-2024-27801
CVE-2024-5868
CVE-2024-0582
CVE-2024-37643
CVE-2024-3105
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
NEXT »