ISOMAN

Release

SmoothWall Express 3.0-sp3

SmoothWall Express · 4 targets · 4 artifacts

Release Facts

Version
3.0-sp3
Date
Architectures
i386, x86_64
Editions
express
Variants
dev, standard
Protocols
https

Quality

Targets
4
Artifacts
4
Checksums
8/4
Average confidence
1.00
CVEs
5

Artifacts

ArtifactMediaSizeProtocolsChecksumsQuality
smoothwall-express-3.0-sp3-devel-i386.isoiso174 MBhttps21.00
smoothwall-express-3.0-sp3-devel-x86_64.isoiso180 MBhttps21.00
smoothwall-express-3.0-sp3-i386.isoiso111 MBhttps21.00
smoothwall-express-3.0-sp3-x86_64.isoiso116 MBhttps21.00

Related CVEs

  1. CVE-2011-5283

    MEDIUM · Cross-site scripting (XSS) vulnerability in the web management interface in httpd/cgi-bin/ipinfo.cgi in Smoothwall Express 3.1 and 3.0 SP3 and earlier allows remote attackers to inject arbitrary web script or HTML via the IP parameter in a Run action.

  2. CVE-2011-5284

    MEDIUM · Cross-site request forgery (CSRF) vulnerability in the web management interface in httpd/cgi-bin/shutdown.cgi in Smoothwall Express 3.1 and 3.0 SP3 and earlier allows remote attackers to hijack the authentication of administrators for requests that perform a reboot via a request to cgi-bin/shutdown.cgi.

  3. CVE-2014-9429

    MEDIUM · Multiple cross-site scripting (XSS) vulnerabilities in Smoothwall Express 3.1 and 3.0 SP3 allow remote attackers to inject arbitrary web script or HTML via the (1) PROFILENAME parameter in a Save action to httpd/cgi-bin/pppsetup.cgi or (2) COMMENT parameter in an Add action to httpd/cgi-bin/ddns.cgi.

  4. CVE-2014-9430

    MEDIUM · Cross-site scripting (XSS) vulnerability in httpd/cgi-bin/vpn.cgi/vpnconfig.dat in Smoothwall Express 3.0 SP3 allows remote attackers to inject arbitrary web script or HTML via the COMMENT parameter in an Add action.

  5. CVE-2014-9431

    MEDIUM · Multiple cross-site request forgery (CSRF) vulnerabilities in Smoothwall Express 3.1 and 3.0 SP3 allow remote attackers to hijack the authentication of administrators for requests that change the (1) admin or (2) dial password via a request to httpd/cgi-bin/changepw.cgi.