RSS   Vulnerabilities for 'Netact'   RSS

2021-03-25
 
CVE-2021-26597

CWE-434
 

 
An issue was discovered in Nokia NetAct 18A. A remote user, authenticated to the NOKIA NetAct Web Page, can visit the Site Configuration Tool web site section and arbitrarily upload potentially dangerous files without restrictions via the /netact/sct dir parameter in conjunction with the operation=upload value.

 
 
CVE-2021-26596

CWE-79
 

 
An issue was discovered in Nokia NetAct 18A. A malicious user can change a filename of an uploaded file to include JavaScript code, which is then stored and executed by a victim's web browser. The most common mechanism for delivering malicious content is to include it as a parameter in a URL that is posted publicly or e-mailed directly to victims. Here, the /netact/sct filename parameter is used.

 

 >>> Vendor: Nokia 38 Products
Ip440 firewall vpn appliance
Firewall appliance
6210 handset
Sgsn dx200
GGSN
Electronic documentation
IPSO
6310i
QT
Series
Affix
9500
3210
7610
N70
Symbian
Groupwise mobile server
Intellisync mobile suite
Intellisync wireless email express
N95
Series 40
6131 nfc
Symbian s60 browser
Nokia pc suite
N810 internet tablet
N82
Qtdemobrowser
Qt creator
Multimedia player
E75 firmware
E75
Pc suite
@vantage commander
I-240w-q gpon ont firmware
8810 4g firmware
Impact
Netact
Bts trs web console


Copyright 2024, cxsecurity.com

 

Back to Top