📦

web_server

Vendor: teamspeak

Actively Exploited 0 CISA KEV List
PoC / Exploits 4 Code Available
Total RCEs 2 Remote Access
Total CVEs 6 Total Indexed
Avg. EPSS 3.81% Exploit Prob.
Latest CVE CVE-2018-25235 Mar 30

Security Vulnerability Index

Page 1 / 1
6.9 CVSS

NetworkActiv Web Server 4.0 contains a buffer overflow vulnerability in the username field of the Security options that allows local attackers to crash the application by supplying an excessively long string. Attackers can trigger a denial of service by entering a crafted username value exceeding the expected buffer size through the Set username interface.

EPSS: 0.22%
7.5 CVSS

In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected.

EPSS: 0.97%
6.1 CVSS

ZEROF Web Server 2.0 allows /admin.back XSS.

EPSS: 3.25%
9.8 CVSS

ZEROF Web Server 2.0 allows /HandleEvent SQL Injection.

EPSS: 8.35%
9.8 CVSS

ZEROF Web Server 1.0 (April 2021) allows SQL Injection via the /HandleEvent endpoint for the login page.

EPSS: 8.55%
5.3 CVSS

An issue was discovered in Amcrest Web Server 2.520.AC00.18.R 2017-06-29 WEB 3.2.1.453504. The login page responds with JavaScript when one tries to authenticate. An attacker who changes the result parameter (to true) in this JavaScript code can bypass authentication and achieve limited privileges (ability to see every option but not modify them).

EPSS: 1.28%
9.8 CVSS
CVE-2017-16934
RCE Exploit Found

The web server on DBL DBLTek devices allows remote attackers to execute arbitrary OS commands by obtaining the admin password via a frame.html?content=/dev/mtdblock/5 request, and then using this password for the HTTP Basic Authentication needed for a change_password.csp request, which supports a "<%%25call system.exec:" string in the passwd parameter.

EPSS: 13.47%
9.8 CVSS

An Arbitrary File Upload issue was discovered in 3S-Smart Software Solutions GmbH CODESYS Web Server. The following versions of CODESYS Web Server, part of the CODESYS WebVisu web browser visualization software, are affected: CODESYS Web Server Versions 2.3 and prior. A specially crafted web server request may allow the upload of arbitrary files (with a dangerous type) to the CODESYS Web Server without authorization which may allow remote code execution.

EPSS: 2.63%
9.8 CVSS

A Stack Buffer Overflow issue was discovered in 3S-Smart Software Solutions GmbH CODESYS Web Server. The following versions of CODESYS Web Server, part of the CODESYS WebVisu web browser visualization software, are affected: CODESYS Web Server Versions 2.3 and prior. A malicious user could overflow the stack buffer by providing overly long strings to functions that handle the XML. Because the function does not verify string size before copying to memory, the attacker may then be able to crash the application or run arbitrary code.

EPSS: 2.00%
4.3 CVSS

Cross-site scripting (XSS) vulnerability in Kantan WEB Server 1.8 and earlier allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

EPSS: 1.22%