2018-08-03 16:04:15 -04:00
|
|
|
{
|
2019-03-18 06:36:41 +00:00
|
|
|
"CVE_data_meta": {
|
|
|
|
"ASSIGNER": "cve@mitre.org",
|
|
|
|
"ID": "CVE-2018-14919",
|
2019-06-28 17:01:02 +00:00
|
|
|
"STATE": "PUBLIC"
|
|
|
|
},
|
|
|
|
"affects": {
|
|
|
|
"vendor": {
|
|
|
|
"vendor_data": [
|
|
|
|
{
|
|
|
|
"product": {
|
|
|
|
"product_data": [
|
|
|
|
{
|
|
|
|
"product_name": "n/a",
|
|
|
|
"version": {
|
|
|
|
"version_data": [
|
|
|
|
{
|
|
|
|
"version_value": "n/a"
|
|
|
|
}
|
|
|
|
]
|
|
|
|
}
|
|
|
|
}
|
|
|
|
]
|
|
|
|
},
|
|
|
|
"vendor_name": "n/a"
|
|
|
|
}
|
|
|
|
]
|
|
|
|
}
|
2019-03-18 06:36:41 +00:00
|
|
|
},
|
|
|
|
"data_format": "MITRE",
|
|
|
|
"data_type": "CVE",
|
|
|
|
"data_version": "4.0",
|
|
|
|
"description": {
|
|
|
|
"description_data": [
|
|
|
|
{
|
|
|
|
"lang": "eng",
|
2019-06-28 17:01:02 +00:00
|
|
|
"value": "LOYTEC LGATE-902 6.3.2 devices allow XSS."
|
|
|
|
}
|
|
|
|
]
|
|
|
|
},
|
|
|
|
"problemtype": {
|
|
|
|
"problemtype_data": [
|
|
|
|
{
|
|
|
|
"description": [
|
|
|
|
{
|
|
|
|
"lang": "eng",
|
|
|
|
"value": "n/a"
|
|
|
|
}
|
|
|
|
]
|
|
|
|
}
|
|
|
|
]
|
|
|
|
},
|
|
|
|
"references": {
|
|
|
|
"reference_data": [
|
|
|
|
{
|
|
|
|
"refsource": "FULLDISC",
|
|
|
|
"name": "20190409 Loytec LGATE-902: Multiple Vulnerabilities (XSS, Path traversal and File Deletion)",
|
|
|
|
"url": "http://seclists.org/fulldisclosure/2019/Apr/12"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"refsource": "MISC",
|
|
|
|
"name": "http://packetstormsecurity.com/files/152453/Loytec-LGATE-902-XSS-Traversal-File-Deletion.html",
|
|
|
|
"url": "http://packetstormsecurity.com/files/152453/Loytec-LGATE-902-XSS-Traversal-File-Deletion.html"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"refsource": "MISC",
|
|
|
|
"name": "https://www.mag-securs.com/alertes/artmid/1894/articleid/41651/loytec-lgate-902-up-to-641-alarm-log-obj-handle-cross-site-scripting.aspx",
|
|
|
|
"url": "https://www.mag-securs.com/alertes/artmid/1894/articleid/41651/loytec-lgate-902-up-to-641-alarm-log-obj-handle-cross-site-scripting.aspx"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"refsource": "FULLDISC",
|
|
|
|
"name": "20190407 Loytec LGATE-902: Multiple Vulnerabilities (XSS, Path traversal and File Deletion)",
|
|
|
|
"url": "https://seclists.org/fulldisclosure/2019/Apr/12"
|
2019-03-18 06:36:41 +00:00
|
|
|
}
|
|
|
|
]
|
|
|
|
}
|
|
|
|
}
|