CVE-2018-1200
published 2018-03-16CVE-2018-1200: Apps Manager for PCF (Pivotal Application Service 1.11.x before 1.11.26, 1.12.x before 1.12.14, and 2.0.x before 2.0.5) allows unprivileged remote file read in…
PriorityP431medium6.5CVSS 3.0
AVNACLPRNUIRSUCHINAN
EPSS
1.35%
68.1th percentile
Apps Manager for PCF (Pivotal Application Service 1.11.x before 1.11.26, 1.12.x before 1.12.14, and 2.0.x before 2.0.5) allows unprivileged remote file read in its container via specially-crafted links.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dell_emc | apps_manager_for_pcf | — | — |
| pivotal_software | pivotal_application_service | >= 1.11.0 < 1.11.26 | 1.11.26 |
| pivotal_software | pivotal_application_service | >= 1.12.0 < 1.12.14 | 1.12.14 |
| pivotal_software | pivotal_application_service | >= 2.0.0 < 2.0.5 | 2.0.5 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
Siemens SIMATIC S7-1200 CPU - Cross-Site Scripting
exploitdb·2018-05-22·CVSS 4.3
CVE-2014-2908 [MEDIUM] Siemens SIMATIC S7-1200 CPU - Cross-Site Scripting
Siemens SIMATIC S7-1200 CPU - Cross-Site Scripting
---
# Exploit Title: Siemens SIMATIC S7-1200 CPU - Cross-Site Scripting
# Google Dork: inurl:/Portal/Portal.mwsl
# Date: 2018-05-22
# Exploit Author: t4rkd3vilz, Jameel Nabbo
# Vendor Homepage: https://www.siemens.com/
# Version: SIMATIC S7-1200 CPU family Versions: V2.X and V3.X.
# Tested on: Kali Linux
# CVE: CVE-2014-2908
http://TargetIp/Portal/Portal.mwsl?PriNav=Bgz&filtername=Name&filtervalue=
">&Send=Filter
Exploit-DB
Siemens SIMATIC S7-1200 CPU - Cross-Site Request Forgery
exploitdb·2018-05-21
Siemens SIMATIC S7-1200 CPU - Cross-Site Request Forgery
Siemens SIMATIC S7-1200 CPU - Cross-Site Request Forgery
---
# Exploit Title: Siemens SIMATIC S7-1200 CPU - Cross-Site Request Forgery
# Google Dork: inurl:/Portal/Portal.mwsl
# Date: 2018-05-21
# Exploit Author: t4rkd3vilz, Jameel Nabbo
# Vendor Homepage: https://www.siemens.com/
# Version: SIMATIC S7-1200 CPU family: All versions prior to V4.1.3
# Tested on: Kali Linux
# CVE: CVE-2015- 5698
# 1. Proof of Concept
No writeups or analysis indexed.
2018-03-16
Published