An issue was discovered in Poly EagleEye Director II before 2.2.2.1. os.system command injection can be achieved by an admin.Read More ...
Continue ReadingJuly 17, 2022
An issue was discovered in Poly Studio before 3.7.0. Command Injection can occur via the CN field of a Create Certificate Signing Request (CSR) action.Read More ...
Continue ReadingJuly 17, 2022
An issue was discovered in Infiray IRAY-A8Z3 1.0.957. The binary file /usr/local/sbin/webproject/set_param.cgi contains hardcoded credentials to the web application. Because these accounts cannot be d ...
Continue ReadingJuly 17, 2022
An issue was discovered in Infiray IRAY-A8Z3 1.0.957. There is a blank root password for TELNET by default.Read More ...
Continue ReadingJuly 17, 2022
libnx_apl.so on Nexans FTTO GigaSwitch before 6.02N and 7.x before 7.02 implements a Backdoor Account for SSH logins on port 50200 or 50201.Read More ...
Continue ReadingJuly 17, 2022
An issue was discovered in Gentics CMS before 5.43.1. By uploading a malicious ZIP file, an attacker is able to deserialize arbitrary data and hence can potentially achieve Java code execution.Read Mo ...
Continue ReadingJuly 17, 2022
Pexip Infinity 27.x before 27.3 allows remote attackers to trigger a software abort via HTTP.Read More ...
Continue ReadingJuly 17, 2022
In Montala ResourceSpace through 9.8 before r19636, csv_export_results_metadata.php allows attackers to export collection metadata via a non-NULL k value.Read More ...
Continue ReadingJuly 17, 2022
Back to Main