| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2016-10886 | Cri | 0.64 | 9.8 | 0.02 | Aug 14, 2019 | The wp-editor plugin before 1.2.6 for WordPress has incorrect permissions. | ||
| CVE-2015-9310 | Cri | 0.64 | 9.8 | 0.02 | Aug 14, 2019 | The all-in-one-wp-security-and-firewall plugin before 3.9.1 for WordPress has multiple SQL injection issues. | ||
| CVE-2019-15025 | Cri | 0.64 | 9.8 | 0.02 | Aug 14, 2019 | The ninja-forms plugin before 3.3.21.2 for WordPress has SQL injection in the search filter on the submissions page. | ||
| CVE-2017-18514 | Cri | 0.64 | 9.8 | 0.02 | Aug 14, 2019 | The simple-login-log plugin before 1.1.2 for WordPress has SQL injection. | ||
| CVE-2016-10889 | Cri | 0.64 | 9.8 | 0.02 | Aug 14, 2019 | The nextgen-gallery plugin before 2.1.57 for WordPress has SQL injection via a gallery name. | ||
| CVE-2015-9316 | Cri | 0.64 | 9.8 | 0.03 | Aug 14, 2019 | The wp-fastest-cache plugin before 0.8.4.9 for WordPress has SQL injection in wp-admin/admin-ajax.php?action=wpfc_wppolls_ajax_request via the poll_id parameter. | ||
| CVE-2015-9315 | Cri | 0.64 | 9.8 | 0.02 | Aug 14, 2019 | The newstatpress plugin before 1.0.1 for WordPress has SQL injection. | ||
| CVE-2015-9313 | Cri | 0.64 | 9.8 | 0.02 | Aug 14, 2019 | The newstatpress plugin before 1.0.5 for WordPress has SQL injection related to an IMG element. | ||
| CVE-2019-0345 | Cri | 0.64 | 9.8 | 0.02 | Aug 14, 2019 | A remote unauthenticated attacker can abuse a web service in SAP NetWeaver Application Server for Java (Administrator System Overview), versions 7.30, 7.31, 7.40, 7.50, by sending a specially crafted XML file and trick the application server into leaking authentication… | ||
| CVE-2019-0344 | Cri | 0.76 | 9.8 | 0.07 | KEV | Aug 14, 2019 | Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to execute arbitrary code on a target machine with 'Hybris' user rights, resulting in Code Injection. | |
| CVE-2017-18515 | Cri | 0.57 | 9.8 | 0.03 | Aug 14, 2019 | The wp-statistics plugin before 12.0.8 for WordPress has SQL injection. | ||
| CVE-2019-15027 | Cri | 0.64 | 9.8 | 0.03 | Aug 14, 2019 | The MediaTek Embedded Multimedia Card (eMMC) subsystem for Android on MT65xx, MT66xx, and MT8163 SoC devices allows attackers to execute arbitrary commands as root via shell metacharacters in a filename under /data, because clear_emmc_nomedia_entry in… | ||
| CVE-2019-14809 | Cri | 0.64 | 9.8 | 0.08 | Aug 13, 2019 | net/url in Go before 1.11.13 and 1.12.x before 1.12.8 mishandles malformed hosts in URLs, leading to an authorization bypass in some applications. This is related to a Host field with a suffix appearing in neither Hostname() nor Port(), and is related to a non-numeric port… | ||
| CVE-2019-12479 | Cri | 0.59 | 9.1 | 0.02 | Aug 13, 2019 | An issue was discovered in 20|20 Storage 2.11.0. A Path Traversal vulnerability in the TwentyTwenty.Storage library in the LocalStorageProvider allows creating and reading files outside of the specified basepath. If the application using this library does not sanitize… | ||
| CVE-2019-14985 | Cri | 0.64 | 9.8 | 0.08 | Aug 13, 2019 | eQ-3 Homematic CCU2 and CCU3 with the CUxD AddOn installed allow Remote Code Execution by unauthenticated attackers with access to the web interface, because this interface can access the CMD_EXEC virtual device type 28. | ||
| CVE-2015-9301 | Cri | 0.64 | 9.8 | 0.02 | Aug 13, 2019 | The liveforms plugin before 3.2.0 for WordPress has SQL injection. | ||
| CVE-2015-9298 | Cri | 0.64 | 9.8 | 0.02 | Aug 13, 2019 | The events-manager plugin before 5.6 for WordPress has code injection. | ||
| CVE-2019-14968 | Cri | 0.64 | 9.8 | 0.02 | Aug 12, 2019 | An issue was discovered in imcat 4.9. There is SQL Injection via the index.php order parameter in a mod=faqs action. | ||
| CVE-2019-14965 | Cri | 0.64 | 9.8 | 0.03 | Aug 12, 2019 | An issue was discovered in Frappe Framework 10 through 12 before 12.0.4. A server side template injection (SSTI) issue exists. | ||
| CVE-2019-13462 | Cri | 0.60 | 9.1 | 0.11 | Aug 12, 2019 | Lansweeper before 7.1.117.4 allows unauthenticated SQL injection. | ||
| CVE-2019-12618 | Cri | 0.64 | 9.8 | 0.02 | Aug 12, 2019 | HashiCorp Nomad 0.9.0 through 0.9.1 has Incorrect Access Control via the exec driver. | ||
| CVE-2019-12261 | Cri | 0.64 | 9.8 | 0.09 | Aug 9, 2019 | Wind River VxWorks 6.7 though 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 3 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion during connect() to a remote host. | ||
| CVE-2019-12260 | Cri | 0.66 | 9.8 | 0.23 | Aug 9, 2019 | Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 2 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion caused by a malformed TCP AO option. | ||
| CVE-2019-12255 | Cri | 0.73 | 9.8 | 0.75 | Aug 9, 2019 | Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TCP Urgent Pointer = 0 that leads to an integer underflow. | ||
| CVE-2019-11581 | Cri | 0.82 | 9.8 | 0.85 | KEV | Aug 9, 2019 | There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An attacker is able to remotely execute code on systems that run a vulnerable version of Jira Server or Data Center. All versions… | |
| CVE-2019-5402 | Cri | 0.61 | 9.4 | 0.04 | Aug 9, 2019 | A remote authorization bypass vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1. | ||
| CVE-2019-5399 | Cri | 0.61 | 9.4 | 0.02 | Aug 9, 2019 | A remote gain authorized access vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1. | ||
| CVE-2019-5397 | Cri | 0.61 | 9.4 | 0.04 | Aug 9, 2019 | A remote bypass of security restrictions vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1. | ||
| CVE-2019-12256 | Cri | 0.66 | 9.8 | 0.27 | Aug 9, 2019 | Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the IPv4 component. There is an IPNET security vulnerability: Stack overflow in the parsing of IPv4 packets’ IP options. | ||
| CVE-2019-5396 | Cri | 0.62 | 9.4 | 0.05 | Aug 9, 2019 | A remote authentication bypass vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1. | ||
| CVE-2019-14801 | Cri | 0.64 | 9.8 | 0.02 | Aug 9, 2019 | The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows email subscription SQL injection. | ||
| CVE-2019-14234 | Cri | 0.61 | 9.8 | 0.48 | Aug 9, 2019 | An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to an error in shallow key transformation, key and index lookups for django.contrib.postgres.fields.JSONField, and key lookups for django.contrib.postgres.fields.HStoreField,… | ||
| CVE-2018-20955 | Cri | 0.64 | 9.8 | 0.02 | Aug 8, 2019 | Swann SWWHD-INTCAM-HD devices have the twipc root password, leading to FTP access as root. NOTE: all affected customers were migrated by 2020-08-31. | ||
| CVE-2019-12994 | Cri | 0.60 | 9.1 | 0.04 | Aug 8, 2019 | Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer version 6.2.0 for the AJaxServlet servlet via a parameter in a URL. | ||
| CVE-2019-11208 | Cri | 0.64 | 9.9 | 0.01 | Aug 8, 2019 | The authorization component of TIBCO Software Inc.'s TIBCO API Exchange Gateway, and TIBCO API Exchange Gateway Distribution for TIBCO Silver Fabric contains a vulnerability that theoretically processes OAuth authorization incorrectly, leading to potential escalation of… | ||
| CVE-2019-14754 | Cri | 0.64 | 9.8 | 0.02 | Aug 8, 2019 | Open-School 3.0, and Community Edition 2.3, allows SQL Injection via the index.php?r=students/students/document id parameter. | ||
| CVE-2019-14255 | Cri | 0.64 | 9.8 | 0.02 | Aug 8, 2019 | A Server Side Request Forgery (SSRF) vulnerability in go-camo up to version 1.1.4 allows a remote attacker to perform HTTP requests to internal endpoints. | ||
| CVE-2019-13101 | Cri | 0.72 | 9.8 | 0.67 | Aug 8, 2019 | An issue was discovered on D-Link DIR-600M 3.02, 3.03, 3.04, and 3.06 devices. wan.htm can be accessed directly without authentication, which can lead to disclosure of information about the WAN, and can also be leveraged by an attacker to modify the data fields of the page. | ||
| CVE-2019-1971 | Cri | 0.64 | 9.8 | 0.04 | Aug 8, 2019 | A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to perform a command injection attack and execute arbitrary commands with root privileges. The vulnerability is due to insufficient input… | ||
| CVE-2019-14771 | Cri | 0.64 | 9.8 | 0.03 | Aug 8, 2019 | Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3 allows the upload of entire-site configuration archives through the user interface or command line. It does not sufficiently check uploaded archives for invalid data, potentially allowing non-configuration scripts to be… | ||
| CVE-2019-1895 | Cri | 0.64 | 9.8 | 0.02 | Aug 7, 2019 | A vulnerability in the Virtual Network Computing (VNC) console implementation of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to access the VNC console session of an administrative user on an affected device. The… | ||
| CVE-2019-5476 | Cri | 0.64 | 9.8 | 0.02 | Aug 7, 2019 | An SQL Injection in the Nextcloud Lookup-Server < v0.3.0 (running on https://lookup.nextcloud.com) caused unauthenticated users to be able to execute arbitrary SQL commands. | ||
| CVE-2019-14537 | Cri | 0.64 | 9.8 | 0.06 | Aug 7, 2019 | YOURLS through 1.7.3 is affected by a type juggling vulnerability in the api component that can result in login bypass. | ||
| CVE-2019-14746 | Cri | 0.64 | 9.8 | 0.01 | Aug 7, 2019 | A issue was discovered in KuaiFanCMS 5.0. It allows eval injection by placing PHP code in the install.php db_name parameter and then making a config.php request. | ||
| CVE-2018-20961 | Cri | 0.64 | 9.8 | 0.06 | Aug 7, 2019 | In the Linux kernel before 4.16.4, a double free vulnerability in the f_midi_set_alt function of drivers/usb/gadget/function/f_midi.c in the f_midi driver may allow attackers to cause a denial of service or possibly have unspecified other impact. | ||
| CVE-2019-1913 | Cri | 0.69 | 9.8 | 0.26 | Aug 7, 2019 | Multiple vulnerabilities in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, remote attacker to overflow a buffer, which then allows the execution of arbitrary code with root privileges on the underlying operating… | ||
| CVE-2019-1912 | Cri | 0.64 | 9.1 | 0.17 | Aug 7, 2019 | A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, remote attacker to upload arbitrary files. The vulnerability is due to incomplete authorization checks in the web management interface. An attacker… | ||
| CVE-2019-14709 | Cri | 0.64 | 9.8 | 0.02 | Aug 6, 2019 | A cleartext password storage issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. The file in question is /usr/local/ipsca/mipsca.db. If a camera is compromised, the attacker can gain access to passwords and abuse them to compromise further… | ||
| CVE-2019-14708 | Cri | 0.64 | 9.8 | 0.04 | Aug 6, 2019 | An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. A buffer overflow in the action parameter leads to remote code execution in the context of the nobody account. | ||
| CVE-2019-14704 | Cri | 0.64 | 9.8 | 0.02 | Aug 6, 2019 | An SSRF issue was discovered in HTTPD on MicroDigital N-series cameras with firmware through 6400.0.8.5 via FTP commands following a newline character in the uploadfile field. |
- risk 0.64cvss 9.8epss 0.02
The wp-editor plugin before 1.2.6 for WordPress has incorrect permissions.
- risk 0.64cvss 9.8epss 0.02
The all-in-one-wp-security-and-firewall plugin before 3.9.1 for WordPress has multiple SQL injection issues.
- risk 0.64cvss 9.8epss 0.02
The ninja-forms plugin before 3.3.21.2 for WordPress has SQL injection in the search filter on the submissions page.
- risk 0.64cvss 9.8epss 0.02
The simple-login-log plugin before 1.1.2 for WordPress has SQL injection.
- risk 0.64cvss 9.8epss 0.02
The nextgen-gallery plugin before 2.1.57 for WordPress has SQL injection via a gallery name.
- risk 0.64cvss 9.8epss 0.03
The wp-fastest-cache plugin before 0.8.4.9 for WordPress has SQL injection in wp-admin/admin-ajax.php?action=wpfc_wppolls_ajax_request via the poll_id parameter.
- risk 0.64cvss 9.8epss 0.02
The newstatpress plugin before 1.0.1 for WordPress has SQL injection.
- risk 0.64cvss 9.8epss 0.02
The newstatpress plugin before 1.0.5 for WordPress has SQL injection related to an IMG element.
- risk 0.64cvss 9.8epss 0.02
A remote unauthenticated attacker can abuse a web service in SAP NetWeaver Application Server for Java (Administrator System Overview), versions 7.30, 7.31, 7.40, 7.50, by sending a specially crafted XML file and trick the application server into leaking authentication…
- risk 0.76cvss 9.8epss 0.07
Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to execute arbitrary code on a target machine with 'Hybris' user rights, resulting in Code Injection.
- risk 0.57cvss 9.8epss 0.03
The wp-statistics plugin before 12.0.8 for WordPress has SQL injection.
- risk 0.64cvss 9.8epss 0.03
The MediaTek Embedded Multimedia Card (eMMC) subsystem for Android on MT65xx, MT66xx, and MT8163 SoC devices allows attackers to execute arbitrary commands as root via shell metacharacters in a filename under /data, because clear_emmc_nomedia_entry in…
- risk 0.64cvss 9.8epss 0.08
net/url in Go before 1.11.13 and 1.12.x before 1.12.8 mishandles malformed hosts in URLs, leading to an authorization bypass in some applications. This is related to a Host field with a suffix appearing in neither Hostname() nor Port(), and is related to a non-numeric port…
- risk 0.59cvss 9.1epss 0.02
An issue was discovered in 20|20 Storage 2.11.0. A Path Traversal vulnerability in the TwentyTwenty.Storage library in the LocalStorageProvider allows creating and reading files outside of the specified basepath. If the application using this library does not sanitize…
- risk 0.64cvss 9.8epss 0.08
eQ-3 Homematic CCU2 and CCU3 with the CUxD AddOn installed allow Remote Code Execution by unauthenticated attackers with access to the web interface, because this interface can access the CMD_EXEC virtual device type 28.
- risk 0.64cvss 9.8epss 0.02
The liveforms plugin before 3.2.0 for WordPress has SQL injection.
- risk 0.64cvss 9.8epss 0.02
The events-manager plugin before 5.6 for WordPress has code injection.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in imcat 4.9. There is SQL Injection via the index.php order parameter in a mod=faqs action.
- risk 0.64cvss 9.8epss 0.03
An issue was discovered in Frappe Framework 10 through 12 before 12.0.4. A server side template injection (SSTI) issue exists.
- risk 0.60cvss 9.1epss 0.11
Lansweeper before 7.1.117.4 allows unauthenticated SQL injection.
- risk 0.64cvss 9.8epss 0.02
HashiCorp Nomad 0.9.0 through 0.9.1 has Incorrect Access Control via the exec driver.
- risk 0.64cvss 9.8epss 0.09
Wind River VxWorks 6.7 though 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 3 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion during connect() to a remote host.
- risk 0.66cvss 9.8epss 0.23
Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 2 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion caused by a malformed TCP AO option.
- risk 0.73cvss 9.8epss 0.75
Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TCP Urgent Pointer = 0 that leads to an integer underflow.
- risk 0.82cvss 9.8epss 0.85
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An attacker is able to remotely execute code on systems that run a vulnerable version of Jira Server or Data Center. All versions…
- risk 0.61cvss 9.4epss 0.04
A remote authorization bypass vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.
- risk 0.61cvss 9.4epss 0.02
A remote gain authorized access vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1.
- risk 0.61cvss 9.4epss 0.04
A remote bypass of security restrictions vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1.
- risk 0.66cvss 9.8epss 0.27
Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the IPv4 component. There is an IPNET security vulnerability: Stack overflow in the parsing of IPv4 packets’ IP options.
- risk 0.62cvss 9.4epss 0.05
A remote authentication bypass vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1.
- risk 0.64cvss 9.8epss 0.02
The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows email subscription SQL injection.
- risk 0.61cvss 9.8epss 0.48
An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to an error in shallow key transformation, key and index lookups for django.contrib.postgres.fields.JSONField, and key lookups for django.contrib.postgres.fields.HStoreField,…
- risk 0.64cvss 9.8epss 0.02
Swann SWWHD-INTCAM-HD devices have the twipc root password, leading to FTP access as root. NOTE: all affected customers were migrated by 2020-08-31.
- risk 0.60cvss 9.1epss 0.04
Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer version 6.2.0 for the AJaxServlet servlet via a parameter in a URL.
- risk 0.64cvss 9.9epss 0.01
The authorization component of TIBCO Software Inc.'s TIBCO API Exchange Gateway, and TIBCO API Exchange Gateway Distribution for TIBCO Silver Fabric contains a vulnerability that theoretically processes OAuth authorization incorrectly, leading to potential escalation of…
- risk 0.64cvss 9.8epss 0.02
Open-School 3.0, and Community Edition 2.3, allows SQL Injection via the index.php?r=students/students/document id parameter.
- risk 0.64cvss 9.8epss 0.02
A Server Side Request Forgery (SSRF) vulnerability in go-camo up to version 1.1.4 allows a remote attacker to perform HTTP requests to internal endpoints.
- risk 0.72cvss 9.8epss 0.67
An issue was discovered on D-Link DIR-600M 3.02, 3.03, 3.04, and 3.06 devices. wan.htm can be accessed directly without authentication, which can lead to disclosure of information about the WAN, and can also be leveraged by an attacker to modify the data fields of the page.
- risk 0.64cvss 9.8epss 0.04
A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to perform a command injection attack and execute arbitrary commands with root privileges. The vulnerability is due to insufficient input…
- risk 0.64cvss 9.8epss 0.03
Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3 allows the upload of entire-site configuration archives through the user interface or command line. It does not sufficiently check uploaded archives for invalid data, potentially allowing non-configuration scripts to be…
- risk 0.64cvss 9.8epss 0.02
A vulnerability in the Virtual Network Computing (VNC) console implementation of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to access the VNC console session of an administrative user on an affected device. The…
- risk 0.64cvss 9.8epss 0.02
An SQL Injection in the Nextcloud Lookup-Server < v0.3.0 (running on https://lookup.nextcloud.com) caused unauthenticated users to be able to execute arbitrary SQL commands.
- risk 0.64cvss 9.8epss 0.06
YOURLS through 1.7.3 is affected by a type juggling vulnerability in the api component that can result in login bypass.
- risk 0.64cvss 9.8epss 0.01
A issue was discovered in KuaiFanCMS 5.0. It allows eval injection by placing PHP code in the install.php db_name parameter and then making a config.php request.
- risk 0.64cvss 9.8epss 0.06
In the Linux kernel before 4.16.4, a double free vulnerability in the f_midi_set_alt function of drivers/usb/gadget/function/f_midi.c in the f_midi driver may allow attackers to cause a denial of service or possibly have unspecified other impact.
- risk 0.69cvss 9.8epss 0.26
Multiple vulnerabilities in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, remote attacker to overflow a buffer, which then allows the execution of arbitrary code with root privileges on the underlying operating…
- risk 0.64cvss 9.1epss 0.17
A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, remote attacker to upload arbitrary files. The vulnerability is due to incomplete authorization checks in the web management interface. An attacker…
- risk 0.64cvss 9.8epss 0.02
A cleartext password storage issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. The file in question is /usr/local/ipsca/mipsca.db. If a camera is compromised, the attacker can gain access to passwords and abuse them to compromise further…
- risk 0.64cvss 9.8epss 0.04
An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. A buffer overflow in the action parameter leads to remote code execution in the context of the nobody account.
- risk 0.64cvss 9.8epss 0.02
An SSRF issue was discovered in HTTPD on MicroDigital N-series cameras with firmware through 6400.0.8.5 via FTP commands following a newline character in the uploadfile field.