Show filters
48 Total Results
Displaying 1-10 of 48
Sort by:
Attacker Value
Unknown
CVE-2022-26978
Disclosure Date: June 02, 2022 (last updated February 23, 2025)
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a URL /checklogin.jsp endpoint. The os_username parameters is not correctly sanitized, leading to reflected XSS.
0
Attacker Value
Unknown
CVE-2022-26977
Disclosure Date: June 02, 2022 (last updated February 23, 2025)
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. Lack of input sanitization of the upload mechanism is leads to stored XSS.
0
Attacker Value
Unknown
CVE-2022-26976
Disclosure Date: June 02, 2022 (last updated February 23, 2025)
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. Lack of input sanitization in the upload mechanism is leads to reflected XSS.
0
Attacker Value
Unknown
CVE-2022-26975
Disclosure Date: June 02, 2022 (last updated February 23, 2025)
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing log files without authentication.
0
Attacker Value
Unknown
CVE-2022-26974
Disclosure Date: June 02, 2022 (last updated February 23, 2025)
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a file upload mechanism. Lack of input sanitization in the upload mechanism leads to reflected XSS.
0
Attacker Value
Unknown
CVE-2022-26973
Disclosure Date: June 02, 2022 (last updated February 23, 2025)
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. By tweaking the license file name, the returned error message exposes internal directory path details.
0
Attacker Value
Unknown
CVE-2022-26972
Disclosure Date: June 02, 2022 (last updated February 23, 2025)
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a URL /cgi-bin endpoint. The URL parameters are not correctly sanitized, leading to reflected XSS.
0
Attacker Value
Unknown
CVE-2022-26971
Disclosure Date: June 02, 2022 (last updated February 23, 2025)
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. This upload can be executed without authentication.
0
Attacker Value
Unknown
CVE-2022-26233
Disclosure Date: April 03, 2022 (last updated February 23, 2025)
Barco Control Room Management through Suite 2.9 Build 0275 was discovered to be vulnerable to directory traversal, allowing attackers to access sensitive information and components. Requests must begin with the "GET /..\.." substring.
0
Attacker Value
Unknown
CVE-2021-38142
Disclosure Date: September 07, 2021 (last updated February 23, 2025)
Barco MirrorOp Windows Sender before 2.5.3.65 uses cleartext HTTP and thus allows rogue software upgrades. An attacker on the local network can achieve remote code execution on any computer that tries to update Windows Sender due to the fact that the upgrade mechanism is not secured (is not protected with TLS).
0