Show filters
39 Total Results
Displaying 21-30 of 39
Sort by:
Attacker Value
Unknown
CVE-2020-35558
Disclosure Date: February 16, 2021 (last updated February 22, 2025)
An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual through 2.11.2. There is an SSRF in the in the MySQL access check, allowing an attacker to scan for open ports and gain some information about possible credentials.
0
Attacker Value
Unknown
CVE-2020-35567
Disclosure Date: February 16, 2021 (last updated February 22, 2025)
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. The software uses a secure password for database access, but this password is shared across instances.
0
Attacker Value
Unknown
CVE-2020-35565
Disclosure Date: February 16, 2021 (last updated February 22, 2025)
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. The login pages bruteforce detection is disabled by default.
0
Attacker Value
Unknown
CVE-2020-35569
Disclosure Date: February 16, 2021 (last updated February 22, 2025)
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is a self XSS issue with a crafted cookie in the login page.
0
Attacker Value
Unknown
CVE-2020-35560
Disclosure Date: February 16, 2021 (last updated February 22, 2025)
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an unauthenticated open redirect in the redirect.php.
0
Attacker Value
Unknown
CVE-2020-35570
Disclosure Date: February 16, 2021 (last updated February 22, 2025)
An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual through 2.11.2. An unauthenticated attacker is able to access files (that should have been restricted) via forceful browsing.
0
Attacker Value
Unknown
CVE-2020-35561
Disclosure Date: February 16, 2021 (last updated February 22, 2025)
An issue was discovered MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. There is an SSRF in the HA module allowing an unauthenticated attacker to scan for open ports.
0
Attacker Value
Unknown
CVE-2020-35566
Disclosure Date: February 16, 2021 (last updated February 22, 2025)
An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. An attacker can read arbitrary JSON files via Local File Inclusion.
0
Attacker Value
Unknown
CVE-2020-12529
Disclosure Date: February 15, 2021 (last updated February 22, 2025)
An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2 There is a SSRF in the LDAP access check, allowing an attacker to scan for open ports.
0
Attacker Value
Unknown
CVE-2020-12530
Disclosure Date: February 15, 2021 (last updated February 22, 2025)
An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2. There is an XSS issue in the redirect.php allowing an attacker to inject code via a get parameter.
0