fast-poster v2.15.0 is vulnerable to Cross Site Scripting (XSS). File upload check binary of img, but without strictly check file suffix at /server/fast.py -> ApiUploadHandler.post causes stored XSS (CVSS:5.4) (Last Update:2023-07-18 15:14:27) Latest security vulnerabilities (Cross Site Scripting (XSS)) (CVSS score >= 4)
TOTOLINK Wireless Routers Remote Command Execution
Multiple TOTOLINK network products contain a command injection vulnerability in setting/setTracerouteCfg. This vulnerability allows an attacker to execute arbitrary commands through the command parameter. After