Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown
CVE-2020-10581
Disclosure Date: March 25, 2021 (last updated February 22, 2025)
Multiple session validity check issues in several administration functionalities of Invigo Automatic Device Management (ADM) through 5.0 allow remote attackers to read potentially sensitive data hosted by the application.
0
Attacker Value
Unknown
CVE-2020-10584
Disclosure Date: March 25, 2021 (last updated February 22, 2025)
A directory traversal on the /admin/search_by.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote attackers to read arbitrary server files accessible to the user running the application.
0
Attacker Value
Unknown
CVE-2020-10583
Disclosure Date: March 25, 2021 (last updated February 22, 2025)
The /admin/admapi.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote authenticated attackers to execute arbitrary OS commands on the server as the user running the application.
0
Attacker Value
Unknown
CVE-2020-10580
Disclosure Date: March 25, 2021 (last updated February 22, 2025)
A command injection on the /admin/broadcast.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote authenticated attackers to execute arbitrary PHP code on the server as the user running the application.
0
Attacker Value
Unknown
CVE-2020-10579
Disclosure Date: March 25, 2021 (last updated February 22, 2025)
A directory traversal on the /admin/sysmon.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote attackers to list the content of arbitrary server directories accessible to the user running the application.
0
Attacker Value
Unknown
CVE-2020-10582
Disclosure Date: March 25, 2021 (last updated February 22, 2025)
A SQL injection on the /admin/display_errors.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote attackers to execute arbitrary SQL requests (including data reading and modification) on the database.
0