Show filters
129 Total Results
Displaying 11-20 of 129
Sort by:
Attacker Value
Unknown

CVE-2023-47024

Disclosure Date: January 20, 2024 (last updated February 10, 2024)
Cross-Site Request Forgery (CSRF) in NCR Terminal Handler v.1.5.1 leads to a one-click account takeover. This is achieved by exploiting multiple vulnerabilities, including an undisclosed function in the WSDL that has weak security controls and can accept custom content types.
Attacker Value
Unknown

CVE-2021-31314

Disclosure Date: January 20, 2024 (last updated January 27, 2024)
File upload vulnerability in ejinshan v8+ terminal security system allows attackers to upload arbitrary files to arbitrary locations on the server.
Attacker Value
Unknown

CVE-2023-29484

Disclosure Date: October 16, 2023 (last updated October 25, 2023)
In Terminalfour before 8.3.16, misconfigured LDAP users are able to login with an invalid password.
Attacker Value
Unknown

CVE-2023-1049

Disclosure Date: June 14, 2023 (last updated October 08, 2023)
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause execution of malicious code when an unsuspicious user loads a project file from the local filesystem into the HMI.
Attacker Value
Unknown

CVE-2023-1508

Disclosure Date: May 23, 2023 (last updated December 22, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Adam Retail Automation Systems Mobilmen Terminal Software allows SQL Injection.This issue affects Mobilmen Terminal Software: before 3.
Attacker Value
Unknown

CVE-2023-1863

Disclosure Date: April 14, 2023 (last updated December 22, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eskom Water Metering Software allows Command Line Execution through SQL Injection.This issue affects Water Metering Software: before 23.04.06.
Attacker Value
Unknown

CVE-2023-23591

Disclosure Date: April 12, 2023 (last updated October 08, 2023)
The Logback component in Terminalfour before 8.3.14.1 allows OS administrators to obtain sensitive information from application server logs when debug logging is enabled. The fixed versions are 8.2.18.7, 8.2.18.2.2, 8.3.11.1, and 8.3.14.1.
Attacker Value
Unknown

CVE-2023-23558

Disclosure Date: February 16, 2023 (last updated October 08, 2023)
In Eternal Terminal 6.2.1, TelemetryService uses fixed paths in /tmp. For example, a local attacker can create /tmp/.sentry-native-etserver with mode 0777 before the etserver process is started. The attacker can choose to read sensitive information from that file, or modify the information in that file.
Attacker Value
Unknown

CVE-2022-48258

Disclosure Date: January 13, 2023 (last updated October 08, 2023)
In Eternal Terminal 6.2.1, etserver and etclient have world-readable logfiles.
Attacker Value
Unknown

CVE-2022-48257

Disclosure Date: January 13, 2023 (last updated October 08, 2023)
In Eternal Terminal 6.2.1, etserver and etclient have predictable logfile names in /tmp.