An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. A SQL Injection vulnerability allows authenticated users to taint database data and extract sensitive information via crafted HTTP requ ...
Continue ReadingJuly 18, 2022
This vulnerability affects all of the company's products that also include the FW versions: update_i90_cv2.021_b20210104, update_i50_v1.0.55_b20200509, update_x6_v2.1.2_b202001127, update_b5_v2.0.9_b2 ...
Continue ReadingJuly 18, 2022
On Cellinx Camera with guest enabled, attacker with web access can elevate privileges to administrative: "1" to "0" privileges by changing the following cookie values from "is_admin", "showConfig". Ad ...
Continue ReadingJuly 18, 2022
Directory listing is a web server function that displays the directory contents when there is no index file in a specific website directory. A directory listing provides an attacker with the complete ...
Continue ReadingJuly 18, 2022
The server checks the user's cookie in a non-standard way, and a value is entered in the cookie value name of the status and its value is set to true to bypass the identification with the system using ...
Continue ReadingJuly 18, 2022
Browsing the admin.html page allows the user to reset the admin password. Also appears in the JS code for the password.Read More ...
Continue ReadingJuly 18, 2022
ManageEngine Password Manager Pro 12100 and prior and OPManager 126100 and prior are vulnerable to unauthorized file and directory creation on a server machine.Read More ...
Continue ReadingJuly 18, 2022
Allows a remote user to read files on the camera's OS "GetFileContent.cgi". Reading arbitrary files on the camera's OS as root user.Read More ...
Continue ReadingJuly 18, 2022
Back to Main