Fruitywifi Project
fruitywifi_project
5 CVEs • 1 product
Products (1)
Click to collapseToggle
Products (1)
Click to collapse
CVEs (5)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Fruitywifi Project 1Fruitywifi Nov 21, 2024 Nov 5, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A remote code execution vulnerability is identified in FruityWifi through 2.4. Due to improperly escaped shell metacharacters obtained from the POST request at the page_config_adv.php page, it is possible to perform remo...Show more |
FruityWifi through 2.4 has an unsafe Sudo configuration [(ALL : ALL) NOPASSWD: ALL]. This allows an attacker to perform a system-level (root) local privilege escalation, allowing an attacker to gain complete persistent a...Show more |
1Fruitywifi Project 1Fruitywifi Nov 21, 2024 Oct 23, 2020 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 A Cross-Site Request Forgery (CSRF) vulnerability is identified in FruityWifi through 2.4. Due to a lack of CSRF protection in page_config_adv.php, an unauthenticated attacker can lure the victim to visit his website by...Show more |
1Fruitywifi Project 1Fruitywifi Nov 21, 2024 Nov 11, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Shell Metacharacter Injection in www/modules/save.php in FruityWifi (aka PatatasFritas/PatataWifi) through 2.4 allows remote attackers to execute arbitrary code with root privileges via a crafted mod_name parameter in a...Show more |
1Fruitywifi Project 1Fruitywifi Nov 21, 2024 Sep 21, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 FruityWifi (aka PatatasFritas/PatataWifi) 2.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the io_mode, ap_mode, io_action, io_in_iface, io_in_set, io_in_ip, io_in_mask, io_in_gw, io_...Show more |