SecuNinja

2 exploits Active since Oct 2018
CVE-2018-16210 EXPLOITDB MEDIUM text WORKING POC
WAGO 750-88X and 750-89X Ethernet Controller Devices < 01.09.18(13) - Stored Cross-Site Scripting via SNMP Configuration
WAGO 750-88X and WAGO 750-89X Ethernet Controller devices, versions 01.09.18(13) and before, have XSS in the SNMP configuration via the webserv/cplcfg/snmp.ssi SNMP_DESC or SNMP_LOC_SNMP_CONT field.
CVSS 6.1
CVE-2019-15276 EXPLOITDB MEDIUM text WORKING POC
Cisco Wireless LAN Controller Software 8.4-8.9 - Denial of Service via Crafted URL
A vulnerability in the web interface of Cisco Wireless LAN Controller Software could allow a low-privileged, authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability exists due to a failure of the HTTP parsing engine to handle specially crafted URLs. An attacker could exploit this vulnerability by authenticating with low privileges to an affected controller and submitting the crafted URL to the web interface of the affected device. Conversely, an unauthenticated attacker could exploit this vulnerability by persuading a user of the web interface to click the crafted URL. A successful exploit could allow the attacker to cause an unexpected restart of the device, resulting in a DoS condition.
CVSS 6.5