|
212561
|
8.5 |
HIGH
Network
|
ewon
|
ewon_firmware
|
eWON devices with firmware before 10.1s0 do not have an off autocomplete attribute for a password field, which makes it easier for remote attackers to obtain access by leveraging an unattended workst…
|
CWE-200
Information Exposure
|
CVE-2015-7928
|
2024-11-21 11:37 |
2015-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212562
|
6.1 |
MEDIUM
Network
|
ewon
|
ewon_firmware
|
Cross-site scripting (XSS) vulnerability on eWON devices with firmware through 10.1s0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2015-7927
|
2024-11-21 11:37 |
2015-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212563
|
9.9 |
CRITICAL
Network
|
ewon
|
ewon_firmware
|
eWON devices with firmware before 10.1s0 omit RBAC for I/O server information and status requests, which allows remote attackers to obtain sensitive information via an unspecified URL.
|
CWE-200
Information Exposure
|
CVE-2015-7926
|
2024-11-21 11:37 |
2015-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212564
|
8.0 |
HIGH
Network
|
ewon
|
ewon_firmware
|
Cross-site request forgery (CSRF) vulnerability on eWON devices with firmware through 10.1s0 allows remote attackers to hijack the authentication of administrators for requests that trigger firmware …
|
CWE-352
Origin Validation Error
|
CVE-2015-7925
|
2024-11-21 11:37 |
2015-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212565
|
8.8 |
HIGH
Network
|
ewon
|
ewon_firmware
|
eWON devices with firmware before 10.1s0 do not trigger the discarding of browser session data in response to a log-off action, which makes it easier for remote attackers to obtain access by leveragi…
|
NVD-CWE-Other
|
CVE-2015-7924
|
2024-11-21 11:37 |
2015-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212566
|
7.5 |
HIGH
Network
|
motorola
|
moscad_ip_gateway_firmware
|
Cross-site request forgery (CSRF) vulnerability in Motorola Solutions MOSCAD IP Gateway allows remote attackers to hijack the authentication of administrators for requests that modify a password.
|
CWE-352
Origin Validation Error
|
CVE-2015-7936
|
2024-11-21 11:37 |
2015-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212567
|
7.5 |
HIGH
Network
|
motorola
|
moscad_ip_gateway_firmware
|
Motorola Solutions MOSCAD IP Gateway allows remote attackers to read arbitrary files via unspecified vectors.
|
CWE-200
Information Exposure
|
CVE-2015-7935
|
2024-11-21 11:37 |
2015-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212568
|
7.2 |
HIGH
Local
|
opcsystems
|
opc_systems.net
|
Untrusted search path vulnerability in Open Automation OPC Systems.NET 8.00.0023 and earlier allows local users to gain privileges via a Trojan horse DLL in an unspecified directory.
|
NVD-CWE-Other
|
CVE-2015-7917
|
2024-11-21 11:37 |
2015-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212569
|
9.1 |
CRITICAL
Network
|
saia_burgess_controls
|
pcd7.d4xxv_vga_mb_firmware pcd7.d4xxd_firmware pcd3.mxxx0_firmware pcd7.d4xxd_svga_mb_firmware pcd3.t666_firmware pcd1.m2xx0_firmware pcd3.mxx60_firmware pcd3.t665_firmware pc…
|
Saia Burgess PCD1.M0xx0, PCD1.M2xx0, PCD2.M5xx0, PCD3.Mxx60, PCD3.Mxxx0, PCD7.D4xxD, PCD7.D4xxV, PCD7.D4xxWTPF, and PCD7.D4xxxT5F devices before 1.24.50 and PCD3.T665 and PCD3.T666 devices before 1.2…
|
CWE-255
Credentials Management
|
CVE-2015-7911
|
2024-11-21 11:37 |
2015-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212570
|
- |
|
schneider-electric
|
bmxnoe0110h bmxpra0100 bmxnoc0401 bmxnor0200h bmxnoe0100 bmxnor0200 bmxnoe0110 bmxnoe0100h modicon_m340_bmxp342020 modicon_m340_bmxp342030 modicon_m340_bmxp3420302 mo…
|
Stack-based buffer overflow in the GoAhead Web Server on Schneider Electric Modicon M340 PLC BMXNOx and BMXPx devices allows remote attackers to execute arbitrary code via a long password in HTTP Bas…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-7937
|
2024-11-21 11:37 |
2015-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|