Home/Product/seagate nas os
Product

seagate nas os

10 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2018-12304
all versions
Cross-site scripting in Application Manager in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via multiple
6.1MEDIUM
CVE-2018-12303
all versions
Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via directory names.
5.4MEDIUM
CVE-2018-12302
all versions
Missing HTTPOnly flag on session cookies in the Seagate NAS OS version 4.3.15.1 web application allows attackers to steal session
6.1MEDIUM
CVE-2018-12301
all versions
Unvalidated URL in Download Manager in Seagate NAS OS version 4.3.15.1 allows attackers to access the loopback interface via a Dow
7.5HIGH
CVE-2018-12300
all versions
Arbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclose information in the Referer
6.1MEDIUM
CVE-2018-12299
all versions
Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via uploaded file na
5.4MEDIUM
CVE-2018-12298
all versions
Directory Traversal in filebrowser in Seagate NAS OS 4.3.15.1 allows attackers to read files within the application's container vi
7.5HIGH
CVE-2018-12297
all versions
Cross-site scripting in API error pages in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via URL path nam
6.1MEDIUM
CVE-2018-12296
all versions
Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attackers to ob
7.5HIGH
CVE-2018-12295
all versions
SQL injection in folderViewSpecific.psp in Seagate NAS OS version 4.3.15.1 allows attackers to execute arbitrary SQL commands via
9.8CRITICAL
threatengine.sh