For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, adversaries can craft URLs to modify the Document Object Model (DOM) of the page. In addition, adversaries can inject HTML script tags and HTML tags with JavaScript handlers to execute arbitrary JavaScript with the origin of the device.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Lenovo
Subscribe
|
Ez Media \& Backup Center
Subscribe
Ez Media \& Backup Center Firmware
Subscribe
Ix2
Subscribe
Ix2 Firmware
Subscribe
Ix4-300d
Subscribe
Ix4-300d Firmware
Subscribe
Px12-400r
Subscribe
Px12-400r Firmware
Subscribe
Px12-450r
Subscribe
Px12-450r Firmware
Subscribe
Px2-300d
Subscribe
Px2-300d Firmware
Subscribe
Px4-300d
Subscribe
Px4-300d Firmware
Subscribe
Px4-300r
Subscribe
Px4-300r Firmware
Subscribe
Px4-400d
Subscribe
Px4-400d Firmware
Subscribe
Px4-400r
Subscribe
Px4-400r Firmware
Subscribe
Px6-300d
Subscribe
Px6-300d Firmware
Subscribe
Storcenter Ix2
Subscribe
Storcenter Ix2-dl
Subscribe
Storcenter Ix2-dl Firmware
Subscribe
Storcenter Ix2 Firmware
Subscribe
Storcenter Ix4-300d
Subscribe
Storcenter Ix4-300d Firmware
Subscribe
Storcenter Px12-400r
Subscribe
Storcenter Px12-400r Firmware
Subscribe
Storcenter Px12-450r
Subscribe
Storcenter Px12-450r Firmware
Subscribe
Storcenter Px2-300d
Subscribe
Storcenter Px2-300d Firmware
Subscribe
Storcenter Px4-300d
Subscribe
Storcenter Px4-300d Firmware
Subscribe
Storcenter Px4-300r
Subscribe
Storcenter Px4-300r Firmware
Subscribe
Storcenter Px6-300d
Subscribe
Storcenter Px6-300d Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-20682 | For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, adversaries can craft URLs to modify the Document Object Model (DOM) of the page. In addition, adversaries can inject HTML script tags and HTML tags with JavaScript handlers to execute arbitrary JavaScript with the origin of the device. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://support.lenovo.com/us/en/solutions/LEN-24224 |
|
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2024-08-05T07:17:50.623Z
Reserved: 2018-03-27T00:00:00
Link: CVE-2018-9079
No data.
Status : Modified
Published: 2018-09-28T20:29:01.207
Modified: 2024-11-21T04:14:55.907
Link: CVE-2018-9079
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD