Filtered by vendor Lolypop55 Subscriptions
Filtered by product Html5 Snmp Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2019-25294 1 Lolypop55 1 Html5 Snmp 2026-02-09 6.4 Medium
html5_snmp 1.11 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts through the 'Remark' parameter in add_router_operation.php. Attackers can craft a POST request with a script payload in the Remark field to execute arbitrary JavaScript in victim browsers when the page is loaded.
CVE-2019-25298 1 Lolypop55 1 Html5 Snmp 2026-02-09 7.1 High
html5_snmp 1.11 contains multiple SQL injection vulnerabilities that allow attackers to manipulate database queries through Router_ID and Router_IP parameters. Attackers can exploit error-based, time-based, and union-based injection techniques to potentially extract or modify database information by sending crafted payloads.