Show filters
252 Total Results
Displaying 131-140 of 252
Sort by:
Attacker Value
Unknown
CVE-2021-41292
Disclosure Date: September 30, 2021 (last updated February 23, 2025)
ECOA BAS controller suffers from an authentication bypass vulnerability. An unauthenticated attacker through cookie poisoning can remotely bypass authentication and disclose sensitive information and circumvent physical access controls in smart homes and buildings and manipulate HVAC.
0
Attacker Value
Unknown
CVE-2021-41300
Disclosure Date: September 30, 2021 (last updated February 23, 2025)
ECOA BAS controller’s special page displays user account and passwords in plain text, thus unauthenticated attackers can access the page and obtain privilege with full functionality.
0
Attacker Value
Unknown
CVE-2021-41301
Disclosure Date: September 30, 2021 (last updated February 23, 2025)
ECOA BAS controller is vulnerable to configuration disclosure when direct object reference is made to the specific files using an HTTP GET request. This will enable the unauthenticated attacker to remotely disclose sensitive information and help her in authentication bypass, privilege escalation and full system access.
0
Attacker Value
Unknown
CVE-2021-41298
Disclosure Date: September 30, 2021 (last updated February 23, 2025)
ECOA BAS controller is vulnerable to insecure direct object references that occur when the application provides direct access to objects based on user-supplied input. As a result of this vulnerability, attackers with general user's privilege can remotely bypass authorization and access the hidden resources in the system and execute privileged functionalities.
0
Attacker Value
Unknown
CVE-2020-25411
Disclosure Date: May 24, 2021 (last updated February 22, 2025)
Projectworlds Online Examination System 1.0 is vulnerable to CSRF, which allows a remote attacker to delete the existing user.
0
Attacker Value
Unknown
CVE-2020-26006
Disclosure Date: May 24, 2021 (last updated February 22, 2025)
Project Worlds Online Examination System 1.0 is affected by Cross Site Scripting (XSS) via account.php.
0
Attacker Value
Unknown
CVE-2020-21996
Disclosure Date: April 28, 2021 (last updated February 22, 2025)
AVE DOMINAplus <=1.10.x suffers from an unauthenticated reboot command execution. Attackers can exploit this issue to cause a denial of service scenario.
0
Attacker Value
Unknown
CVE-2020-21994
Disclosure Date: April 28, 2021 (last updated February 22, 2025)
AVE DOMINAplus <=1.10.x suffers from clear-text credentials disclosure vulnerability that allows an unauthenticated attacker to issue a request to an unprotected directory that hosts an XML file '/xml/authClients.xml' and obtain administrative login information that allows for a successful authentication bypass attack.
0
Attacker Value
Unknown
CVE-2020-21991
Disclosure Date: April 28, 2021 (last updated February 22, 2025)
AVE DOMINAplus <=1.10.x suffers from an authentication bypass vulnerability due to missing control check when directly calling the autologin GET parameter in changeparams.php script. Setting the autologin value to 1 allows an unauthenticated attacker to permanently disable the authentication security control and access the management interface with admin privileges without providing credentials.
0
Attacker Value
Unknown
CVE-2021-27188
Disclosure Date: February 12, 2021 (last updated February 22, 2025)
The Sovremennye Delovye Tekhnologii FX Aggregator terminal client 1 allows attackers to cause a denial of service (access suspended for five hours) by making five invalid login attempts to a victim's account.
0