VARIoT IoT exploits database

Affected products: vendor, model and version
Type can be e.g: Remote Code Execution or Denial of Service
Look up free text in title and description

VAR-E-201409-0021 CVE-2014-6271
CVE-2014-6278
Qmail SMTP - Bash Environment Variable Injection (Metasploit) - Linux remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201409-1154, VAR-201409-1156
EDB ID: 42938
Qmail SMTP - Bash Environment Variable Injection (Metasploit). CVE-2014-6271CVE-112004 . remote exploit for Linux platform
VAR-E-201409-0016 CVE-2014-6278
CVE-2014-6277
Sun Secure Global Desktop and Oracle Global Desktop 4.61.915 - Command Injection (Shellshock) - CGI webapps Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201409-1154, VAR-201409-0366
EDB ID: 39887
Sun Secure Global Desktop and Oracle Global Desktop 4.61.915 - Command Injection (Shellshock). CVE-2014-6278 . webapps exploit for CGI platform
VAR-E-201409-0020 CVE-2014-6271
CVE-2014-6278
TrendMicro InterScan Web Security Virtual Appliance - 'Shellshock' Remote Command Injection - Hardware remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201409-1154, VAR-201409-1156
EDB ID: 40619
TrendMicro InterScan Web Security Virtual Appliance - 'Shellshock' Remote Command Injection. CVE-2014-6271 . remote exploit for Hardware platform
VAR-E-201409-0547 CVE-2014-7910
CVE-2014-7227
CVE-2014-7196
CVE-2014-7169
CVE-2014-62771
CVE-2014-6271
CVE-2014-3671
CVE-2014-3659
CVE-2014-6277
GNU Bash - 'Shellshock' Environment Variable Command Injection - Linux remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201409-1156, VAR-201409-1155, VAR-201409-0366
EDB ID: 34765
GNU Bash - 'Shellshock' Environment Variable Command Injection. CVE-2014-7910CVE-112004CVE-2014-7227CVE-2014-7196CVE-2014-7169CVE-2014-62771CVE-2014-6271CVE-2014-3671CVE-2014-3659 . remote exploit for Linux platform
VAR-E-201409-0548 CVE-2014-7910
CVE-2014-7227
CVE-2014-7196
CVE-2014-7169
CVE-2014-62771
CVE-2014-6271
CVE-2014-3671
CVE-2014-3659
CVE-2014-6277
GNU Bash - Environment Variable Command Injection (Metasploit) - CGI remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201409-1156, VAR-201409-1155, VAR-201409-0366
EDB ID: 34777
GNU Bash - Environment Variable Command Injection (Metasploit). CVE-2014-7910CVE-112004CVE-2014-7227CVE-2014-7196CVE-2014-7169CVE-2014-62771CVE-2014-6271CVE-2014-3671CVE-2014-3659 . remote exploit for CGI platform
VAR-E-201409-0550 CVE-2014-7910
CVE-2014-7227
CVE-2014-7196
CVE-2014-7169
CVE-2014-62771
CVE-2014-6271
CVE-2014-3671
CVE-2014-3659
CVE-2014-6277
Bash - 'Shellshock' Environment Variables Command Injection - Linux remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201409-1156, VAR-201409-1155, VAR-201409-0366
EDB ID: 34766
Bash - 'Shellshock' Environment Variables Command Injection. CVE-2014-7910CVE-112004CVE-2014-7227CVE-2014-7196CVE-2014-7169CVE-2014-62771CVE-2014-6271CVE-2014-3671CVE-2014-3659 . remote exploit for Linux platform
VAR-E-201409-0015 CVE-2014-7910
CVE-2014-7227
CVE-2014-7196
CVE-2014-7169
CVE-2014-62771
CVE-2014-6271
CVE-2014-3671
CVE-2014-3659
CVE-2014-6277
GNU Bash - 'Shellshock' Environment Variable Command Injection - Linux remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201409-1156, VAR-201409-1155, VAR-201409-0366
EDB ID: 34765
GNU Bash - 'Shellshock' Environment Variable Command Injection. CVE-2014-7910CVE-112004CVE-2014-7227CVE-2014-7196CVE-2014-7169CVE-2014-62771CVE-2014-6271CVE-2014-3671CVE-2014-3659 . remote exploit for Linux platform
VAR-E-201409-0011 CVE-2014-7910
CVE-2014-7227
CVE-2014-7196
CVE-2014-7169
CVE-2014-62771
CVE-2014-6271
CVE-2014-3671
CVE-2014-3659
CVE-2014-6277
GNU Bash - Environment Variable Command Injection (Metasploit) - CGI remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201409-1156, VAR-201409-1155, VAR-201409-0366
EDB ID: 34777
GNU Bash - Environment Variable Command Injection (Metasploit). CVE-2014-7910CVE-112004CVE-2014-7227CVE-2014-7196CVE-2014-7169CVE-2014-62771CVE-2014-6271CVE-2014-3671CVE-2014-3659 . remote exploit for CGI platform
VAR-E-201409-0019 CVE-2014-7910
CVE-2014-7227
CVE-2014-7196
CVE-2014-7169
CVE-2014-62771
CVE-2014-6271
CVE-2014-3671
CVE-2014-3659
CVE-2014-6277
Bash - 'Shellshock' Environment Variables Command Injection - Linux remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201409-1156, VAR-201409-1155, VAR-201409-0366
EDB ID: 34766
Bash - 'Shellshock' Environment Variables Command Injection. CVE-2014-7910CVE-112004CVE-2014-7227CVE-2014-7196CVE-2014-7169CVE-2014-62771CVE-2014-6271CVE-2014-3671CVE-2014-3659 . remote exploit for Linux platform
VAR-E-201409-0073 CVE-2014-6436
CVE-2014-6435
CVE-2014-6437
Aztech Modem Routers - Session Hijacking - Hardware remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201801-0071, VAR-201801-0073, VAR-201801-0072
EDB ID: 39316
Aztech Modem Routers - Session Hijacking. CVE-2014-6436CVE-111433 . remote exploit for Hardware platform
VAR-E-201409-0072 CVE-2014-6437
CVE-2014-6435
CVE-2014-6436
Aztech Modem Routers - Information Disclosure - Hardware remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201801-0071, VAR-201801-0073, VAR-201801-0072
EDB ID: 39314
Aztech Modem Routers - Information Disclosure. CVE-2014-6437CVE-111435 . remote exploit for Hardware platform
VAR-E-201409-0270 No CVE Airties Air6372SO Modem Web Interface 'top.html' Cross Site Scripting Vulnerability No EDB ID
Airties Air6372SO modem web interface is prone to a cross-site-scripting vulnerability because it fails to sufficiently sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
VAR-E-201408-0275 CVE-2014-2927
F5 Big-IP - rsync Access - Hardware remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201410-1053
EDB ID: 34465
F5 Big-IP - rsync Access. CVE-2014-2927 . remote exploit for Hardware platform
VAR-E-201408-0154 CVE-2014-4023
F5 BIG-IP 11.5.1 Cross Site Scripting

Related entries in the VARIoT vulnerabilities database: VAR-201410-0909
No EDB ID
F5 BIG-IP versions 11.5.1 and below suffer from a reflective cross site scripting vulnerability.
VAR-E-201408-0283 CVE-2013-7180
Multiple Cobham Products CVE-2013-7180 Information Disclosure Vulnerability

Related entries in the VARIoT vulnerabilities database: VAR-201408-0034
No EDB ID
Multiple Cobham products are prone to an information-disclosure vulnerability. An attacker can leverage this issue to obtain sensitive information that may lead to further attacks.
VAR-E-201408-0093 CVE-2014-4752
Multiple IBM System Networking Products Hard Coded Credentials Authentication Bypass Vulnerability

Related entries in the VARIoT vulnerabilities database: VAR-201409-0076
No EDB ID
Multiple IBM System Networking Products are prone to an authentication-bypass vulnerability. An attacker can exploit this issue to bypass the authentication mechanism and gain unauthorized access to the affected device. This may aid in further attacks.
VAR-E-201407-0479 No CVE D-Link AP 3200 Missing Authentication / Cleartext Secret Storage No EDB ID
D-Link AP 3200 fails to authenticate requests to wireless settings, stores credentials in plaintext, and uses a weak cookie value.
VAR-E-201407-0249 No CVE D-Link DWL-3200AP Multiple Security Vulnerabilities No EDB ID
D-Link DWL-3200AP is prone to the following security vulnerabilities: 1. A security-bypass vulnerability 2. Multiple information-disclosure vulnerabilities An attacker can exploit these issues to bypass security restrictions or gain access to potentially sensitive information and perform unauthorized actions in the context of a user session. Other attacks are also possible.
VAR-E-201407-0077 No CVE D-Link AP 3200 - Multiple Vulnerabilities - Hardware webapps Exploit EDB ID: 34206
D-Link AP 3200 - Multiple Vulnerabilities. CVE-109787CVE-109786CVE-109785 . webapps exploit for Hardware platform
VAR-E-201407-0115 No CVE Sagem F@st 3304-V1 Denial Of Service No EDB ID
Sagem F@st 3304-V1 suffers from a denial of service vulnerability.