Show filters
27 Total Results
Displaying 11-20 of 27
Sort by:
Attacker Value
Unknown
CVE-2024-3123
Disclosure Date: July 01, 2024 (last updated January 05, 2025)
CHANGING Mobile One Time Password's uploading function in a hidden page does not filter file type properly. Remote attackers with administrator privilege can exploit this vulnerability to upload and run malicious file to execute system commands.
0
Attacker Value
Unknown
CVE-2024-3122
Disclosure Date: July 01, 2024 (last updated January 05, 2025)
CHANGING Mobile One Time Password does not properly filter parameters for the file download functionality, allowing remote attackers with administrator privilege to read arbitrary file on the system.
0
Attacker Value
Unknown
CVE-2023-22901
Disclosure Date: March 31, 2023 (last updated October 08, 2023)
ChangingTec MOTP system has a path traversal vulnerability. A remote attacker with administrator’s privilege can exploit this vulnerability to access arbitrary system files.
0
Attacker Value
Unknown
CVE-2022-39061
Disclosure Date: January 31, 2023 (last updated October 08, 2023)
ChangingTech MegaServiSignAdapter component has a vulnerability of Out-of-bounds Read due to insufficient validation for parameter length. An unauthenticated remote attacker can exploit this vulnerability to access partial sensitive content in memory and disrupts partial services.
0
Attacker Value
Unknown
CVE-2022-39060
Disclosure Date: January 31, 2023 (last updated October 08, 2023)
ChangingTech MegaServiSignAdapter component has a vulnerability of improper input validation. An unauthenticated remote attacker can exploit this vulnerability to access and modify HKEY_CURRENT_USER subkey (ex: AutoRUN) in Registry where malicious scripts can be executed to take control of the system or to terminate the service.
0
Attacker Value
Unknown
CVE-2022-39059
Disclosure Date: January 31, 2023 (last updated October 08, 2023)
ChangingTech MegaServiSignAdapter component has a path traversal vulnerability within its file reading function. An unauthenticated remote attacker can exploit this vulnerability to access arbitrary system files.
0
Attacker Value
Unknown
CVE-2022-46306
Disclosure Date: December 14, 2022 (last updated October 08, 2023)
ChangingTec ServiSign component has a path traversal vulnerability due to insufficient filtering for special characters in the DLL file path. An unauthenticated remote attacker can host a malicious website for the component user to access, which triggers the component to load malicious DLL files under arbitrary file path and allows the attacker to perform arbitrary system operation and disrupt of service.
0
Attacker Value
Unknown
CVE-2022-46305
Disclosure Date: December 14, 2022 (last updated October 08, 2023)
ChangingTec ServiSign component has a path traversal vulnerability. An unauthenticated LAN attacker can exploit this vulnerability to bypass authentication and access arbitrary system files.
0
Attacker Value
Unknown
CVE-2022-46304
Disclosure Date: December 14, 2022 (last updated October 08, 2023)
ChangingTec ServiSign component has insufficient filtering for special characters in the connection response parameter. An unauthenticated remote attacker can host a malicious website for the component user to access, which triggers command injection and allows the attacker to execute arbitrary system command to perform arbitrary system operation or disrupt service.
0
Attacker Value
Unknown
CVE-2022-39058
Disclosure Date: October 18, 2022 (last updated October 08, 2023)
RAVA certification validation system has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and access arbitrary system files.
0