On Cellinx Camera with guest enabled, attacker with web access can elevate privileges to administrative: "1" to "0" privileges by changing the following cookie values from "is_admin", "showConfig". Ad ...
Continue ReadingJuly 18, 2022
Directory listing is a web server function that displays the directory contents when there is no index file in a specific website directory. A directory listing provides an attacker with the complete ...
Continue ReadingJuly 18, 2022
The server checks the user's cookie in a non-standard way, and a value is entered in the cookie value name of the status and its value is set to true to bypass the identification with the system using ...
Continue ReadingJuly 18, 2022
Browsing the admin.html page allows the user to reset the admin password. Also appears in the JS code for the password.Read More ...
Continue ReadingJuly 18, 2022
ManageEngine Password Manager Pro 12100 and prior and OPManager 126100 and prior are vulnerable to unauthorized file and directory creation on a server machine.Read More ...
Continue ReadingJuly 18, 2022
Allows a remote user to read files on the camera's OS "GetFileContent.cgi". Reading arbitrary files on the camera's OS as root user.Read More ...
Continue ReadingJuly 18, 2022
An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. It mishandles access control. This allows a remote attacker to access account information pages (including personal data) without being ...
Continue ReadingJuly 18, 2022
An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. A PresAbs.php SQL Injection vulnerability allows unauthenticated users to taint database data and extract sensitive information via cra ...
Continue ReadingJuly 18, 2022
Back to Main