Summary
Detail | |||
---|---|---|---|
Vendor | Jensenofscandinavia | First view | 2017-04-03 |
Product | al3g Firmware | Last view | 2017-04-03 |
Version | Type | Os | |
Update | |||
Edition | |||
Language | |||
Sofware Edition | |||
Target Software | |||
Target Hardware | |||
Other |
Activity : Overall
COMMON PLATFORM ENUMERATION: Repartition per Version
CPE Name | Affected CVE |
---|---|
cpe:2.3:o:jensenofscandinavia:al3g_firmware:2.23m:*:*:*:*:*:*:* | 5 |
Related : CVE
Date | Alert | Description | |
---|---|---|---|
6.1 | 2017-04-03 | CVE-2016-10316 | Jensen of Scandinavia AS Air:Link 3G (AL3G) version 2.23m (Rev. 3), Air:Link 5000AC (AL5000AC) version 1.13, and Air:Link 59300 (AL59300) version 1.04 (Rev. 4) devices allow remote attackers to conduct Open Redirect attacks via the return-url parameter to /goform/formLogout. |
6.1 | 2017-04-03 | CVE-2016-10315 | Jensen of Scandinavia AS Air:Link 3G (AL3G) version 2.23m (Rev. 3), Air:Link 5000AC (AL5000AC) version 1.13, and Air:Link 59300 (AL59300) version 1.04 (Rev. 4) devices allow remote attackers to conduct Open Redirect attacks via the submit-url parameter to certain /goform/* pages. |
8.8 | 2017-04-03 | CVE-2016-10314 | Jensen of Scandinavia AS Air:Link 3G (AL3G) version 2.23m (Rev. 3), Air:Link 5000AC (AL5000AC) version 1.13, and Air:Link 59300 (AL59300) version 1.04 (Rev. 4) devices allow remote attackers to read passwords via a direct request to the x.asp page. |
8.8 | 2017-04-03 | CVE-2016-10313 | Jensen of Scandinavia AS Air:Link 3G (AL3G) version 2.23m (Rev. 3), Air:Link 5000AC (AL5000AC) version 1.13, and Air:Link 59300 (AL59300) version 1.04 (Rev. 4) devices allow remote attackers to conduct CSRF attacks via certain /goform/* pages. |
9.8 | 2017-04-03 | CVE-2016-10312 | Jensen of Scandinavia AS Air:Link 3G (AL3G) version 2.23m (Rev. 3), Air:Link 5000AC (AL5000AC) version 1.13, and Air:Link 59300 (AL59300) version 1.04 (Rev. 4) devices allow remote attackers to execute arbitrary commands via shell metacharacters to certain /goform/* pages. |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
40% (2) | CWE-601 | URL Redirection to Untrusted Site ('Open Redirect') |
20% (1) | CWE-352 | Cross-Site Request Forgery (CSRF) |
20% (1) | CWE-200 | Information Exposure |
20% (1) | CWE-77 | Improper Sanitization of Special Elements used in a Command ('Comma... |