Skip to main content

Vendor archive

ozeki CVEs

Beta · best-effort

12 CVEs tagged to vendor ozeki0 Critical, 7 High, 4 Medium, 1 Low, 0 Unrated.

CVE-2020-14030

Published Sep 30, 2020

An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. It stores SMS messages in .NET serialized format on the filesystem. By generating (and writing to the disk) malicio…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-14031

Published Sep 22, 2020

An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. The outbox functionality of the TXT File module can be used to delete all/most files in a folder. Because the produ…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-14028

Published Sep 22, 2020

An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. By leveraging a path traversal vulnerability in the Autoreply module's Script Name, an attacker may write to or ove…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-14027

Published Sep 22, 2020

An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. The database connection strings accept custom unsafe arguments, such as ENABLE_LOCAL_INFILE, that can be leveraged…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-14026

Published Sep 22, 2020

CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the Export Of Contacts feature in Ozeki NG SMS Gateway through 4.17.6 via a value that is mishandled in a…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-14025

Published Sep 22, 2020

Ozeki NG SMS Gateway through 4.17.6 has multiple CSRF vulnerabilities. For example, an administrator, by following a link, can be tricked into making unwanted changes such as inst…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-14024

Published Sep 22, 2020

Ozeki NG SMS Gateway through 4.17.6 has multiple authenticated stored and/or reflected XSS vulnerabilities via the (1) Receiver or Recipient field in the Mailbox feature, (2) OZFO…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-14022

Published Sep 22, 2020

Ozeki NG SMS Gateway 4.17.1 through 4.17.6 does not check the file type when bulk importing new contacts ("Import Contacts" functionality) from a file. It is possible to upload an…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-14029

Published Sep 18, 2020

An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. The RSS To SMS module processes XML files in an unsafe manner. This opens the application to an XML External Entity…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-14021

Published Sep 18, 2020

An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. The ASP.net SMS module can be used to read and validate the source code of ASP files. By altering the path, it can…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6674

Published Dec 21, 2006

Ozeki HTTP-SMS Gateway 1.0, and possibly earlier, stores usernames and passwords in plaintext in the HKLM\Software\Ozeki\SMSServer\CurrentVersion\Plugins\httpsmsgate registry key,…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort
Showing 1-12 of 12 CVEsPage 1 of 1