Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown
CVE-2019-18866
Disclosure Date: May 07, 2020 (last updated February 21, 2025)
Unauthenticated SQL injection via the username in the login mechanism in Blaauw Remote Kiln Control through v3.00r4 allows a user to extract arbitrary data from the rkc database.
0
Attacker Value
Unknown
CVE-2019-18870
Disclosure Date: May 07, 2020 (last updated February 21, 2025)
A path traversal via the iniFile parameter in excel.php in Blaauw Remote Kiln Control through v3.00r4 allows an authenticated attacker to download arbitrary files from the host machine.
0
Attacker Value
Unknown
CVE-2019-18869
Disclosure Date: May 07, 2020 (last updated February 21, 2025)
Leftover Debug Code in Blaauw Remote Kiln Control through v3.00r4 allows a user to execute arbitrary php code via /default.php?idx=17.
0
Attacker Value
Unknown
CVE-2019-18864
Disclosure Date: May 07, 2020 (last updated November 27, 2024)
/server-info and /server-status in Blaauw Remote Kiln Control through v3.00r4 allow an unauthenticated attacker to gain sensitive information about the host machine.
0
Attacker Value
Unknown
CVE-2019-18871
Disclosure Date: May 07, 2020 (last updated February 21, 2025)
A path traversal in debug.php accessed via default.php in Blaauw Remote Kiln Control through v3.00r4 allows an authenticated attacker to upload arbitrary files, leading to arbitrary remote code execution.
0
Attacker Value
Unknown
CVE-2019-18872
Disclosure Date: May 07, 2020 (last updated February 21, 2025)
Weak password requirements in Blaauw Remote Kiln Control through v3.00r4 allow a user to set short or guessable passwords (e.g., 1 or 1234).
0
Attacker Value
Unknown
CVE-2019-18865
Disclosure Date: May 07, 2020 (last updated February 21, 2025)
Information disclosure via error message discrepancies in authentication functions in Blaauw Remote Kiln Control through v3.00r4 allows an unauthenticated attacker to enumerate valid usernames.
0
Attacker Value
Unknown
CVE-2019-18868
Disclosure Date: May 07, 2020 (last updated February 21, 2025)
Blaauw Remote Kiln Control through v3.00r4 allows an unauthenticated attacker to access MySQL credentials in cleartext in /engine/db.inc, /lang/nl.bak, or /lang/en.bak.
0
Attacker Value
Unknown
CVE-2019-18867
Disclosure Date: May 07, 2020 (last updated February 21, 2025)
Browsable directories in Blaauw Remote Kiln Control through v3.00r4 allow an attacker to enumerate sensitive filenames and locations, including source code. This affects /ajax/, /common/, /engine/, /flash/, /images/, /Images/, /jscripts/, /lang/, /layout/, /programs/, and /sms/.
0