NETGEAR JNR1010 devices before 1.0.0.32 allow webproc?getpage= XSS.
View Full Alert
Related Posts
CVE-2016-11014 (jnr1010_firmware)NETGEAR JNR1010 devices before 1.0.0.32 have Incorrect Access Control because the ok value of the auth cookie is a special case. View Full Alert
CVE-2016-11015 (jnr1010_firmware)NETGEAR JNR1010 devices before 1.0.0.32 allow cgi-bin/webproc CSRF via the :InternetGatewayDevice.X_TWSZ-COM_URL_Filter.BlackList.1.URL parameter. View Full Alert
CVE-2016-10937IMAPFilter through 2.6.12 does not validate the hostname in an SSL certificate. View Full Alert