RSS   Vulnerabilities for 'Remote application server'   RSS

2020-12-25
 
CVE-2020-35710

CWE-200
 

 
Parallels Remote Application Server (RAS) 18 allows remote attackers to discover an intranet IP address because submission of the login form (even with blank credentials) provides this address to the attacker's client for use as a "host" value. In other words, after an attacker's web browser sent a request to the login form, it would automatically send a second request to a RASHTML5Gateway/socket.io URI with something like "host":"192.168.###.###" in the POST data.

 
2020-07-24
 
CVE-2020-15860

NVD-CWE-Other
 

 
Parallels Remote Application Server (RAS) 17.1.1 has a Business Logic Error causing remote code execution. It allows an authenticated user to execute any application in the backend operating system through the web application, despite the affected application not being published. In addition, it was discovered that it is possible to access any host in the internal domain, even if it has no published applications or the mentioned host is no longer associated with that server farm.

 
2018-02-28
 
CVE-2017-9447

CWE-22
 

 
In the web interface of Parallels Remote Application Server (RAS) 15.5 Build 16140, a vulnerability exists due to improper validation of the file path when requesting a resource under the "RASHTML5Gateway" directory. A remote, unauthenticated attacker could exploit this weakness to read arbitrary files from the vulnerable system using path traversal sequences.

 

 >>> Vendor: Parallels 11 Products
Parallels desktop
Confixx
H-sphere
Virtuozzo containers
Parallels virtuozzo
Plesk
Parallels plesk panel
Parallels plesk small business panel
Parallels small business panel
Remote application server
Parallels


Copyright 2024, cxsecurity.com

 

Back to Top