Show filters
78 Total Results
Displaying 41-50 of 78
Sort by:
Attacker Value
Unknown
CVE-2021-37555
Disclosure Date: July 26, 2021 (last updated February 23, 2025)
TX9 Automatic Food Dispenser v3.2.57 devices allow access to a shell as root/superuser, a related issue to CVE-2019-16734. To connect, the telnet service is used on port 23 with the default password of 059AnkJ for the root account. The user can then download the filesystem through preinstalled BusyBox utilities (e.g., tar and nc).
0
Attacker Value
Unknown
CVE-2020-10581
Disclosure Date: March 25, 2021 (last updated February 22, 2025)
Multiple session validity check issues in several administration functionalities of Invigo Automatic Device Management (ADM) through 5.0 allow remote attackers to read potentially sensitive data hosted by the application.
0
Attacker Value
Unknown
CVE-2020-10584
Disclosure Date: March 25, 2021 (last updated February 22, 2025)
A directory traversal on the /admin/search_by.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote attackers to read arbitrary server files accessible to the user running the application.
0
Attacker Value
Unknown
CVE-2020-10583
Disclosure Date: March 25, 2021 (last updated February 22, 2025)
The /admin/admapi.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote authenticated attackers to execute arbitrary OS commands on the server as the user running the application.
0
Attacker Value
Unknown
CVE-2020-10580
Disclosure Date: March 25, 2021 (last updated February 22, 2025)
A command injection on the /admin/broadcast.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote authenticated attackers to execute arbitrary PHP code on the server as the user running the application.
0
Attacker Value
Unknown
CVE-2020-10579
Disclosure Date: March 25, 2021 (last updated February 22, 2025)
A directory traversal on the /admin/sysmon.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote attackers to list the content of arbitrary server directories accessible to the user running the application.
0
Attacker Value
Unknown
CVE-2020-10582
Disclosure Date: March 25, 2021 (last updated February 22, 2025)
A SQL injection on the /admin/display_errors.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote attackers to execute arbitrary SQL requests (including data reading and modification) on the database.
0
Attacker Value
Unknown
CVE-2020-7580
Disclosure Date: June 10, 2020 (last updated February 21, 2025)
A vulnerability has been identified in SIMATIC Automation Tool (All versions < V4 SP2), SIMATIC NET PC Software V14 (All versions < V14 SP1 Update 14), SIMATIC NET PC Software V15 (All versions), SIMATIC NET PC Software V16 (All versions < V16 Upd3), SIMATIC PCS neo (All versions < V3.0 SP1), SIMATIC ProSave (All versions < V17), SIMATIC S7-1500 Software Controller (All versions < V21.8), SIMATIC STEP 7 (TIA Portal) V13 (All versions < V13 SP2 Update 4), SIMATIC STEP 7 (TIA Portal) V14 (All versions < V14 SP1 Update 10), SIMATIC STEP 7 (TIA Portal) V15 (All versions < V15.1 Update 5), SIMATIC STEP 7 (TIA Portal) V16 (All versions < V16 Update 2), SIMATIC STEP 7 V5 (All versions < V5.6 SP2 HF3), SIMATIC WinCC OA V3.16 (All versions < V3.16 P018), SIMATIC WinCC OA V3.17 (All versions < V3.17 P003), SIMATIC WinCC Runtime Advanced (All versions < V16 Update 2), SIMATIC WinCC Runtime Professional V13 (All versions < V13 SP2 Update 4), SIMATIC WinCC Runtime Professional V14 (All versions < …
0
Attacker Value
Unknown
CVE-2015-3150
Disclosure Date: January 14, 2020 (last updated February 21, 2025)
abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows local users to delete or change the ownership of arbitrary files via the problem directory argument to the (1) ChownProblemDir, (2) DeleteElement, or (3) DeleteProblem method.
0
Attacker Value
Unknown
CVE-2015-3159
Disclosure Date: January 14, 2020 (last updated November 28, 2024)
The abrt-action-install-debuginfo-to-abrt-cache help program in Automatic Bug Reporting Tool (ABRT) does not properly handle the process environment before invoking abrt-action-install-debuginfo, which allows local users to gain privileges.
0