|
198371
|
5.3 |
MEDIUM
Network
|
mbconnectline helmholz
|
mbconnect24 mymbconnect24 myrex24.virtual myrex24
|
An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual through 2.11.2. An unauthenticated attacker is able to access files (that should have be…
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2020-35570
|
2024-11-21 14:27 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198372
|
6.1 |
MEDIUM
Network
|
mbconnectline
|
mbconnect24 mymbconnect24
|
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is a self XSS issue with a crafted cookie in the login page.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35569
|
2024-11-21 14:27 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198373
|
4.3 |
MEDIUM
Network
|
mbconnectline helmholz
|
mbconnect24 mymbconnect24 myrex24.virtual myrex24
|
An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. An incomplete filter applied to a database response all…
|
CWE-200
Information Exposure
|
CVE-2020-35568
|
2024-11-21 14:27 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198374
|
7.8 |
HIGH
Local
|
mbconnectline
|
mbconnect24 mymbconnect24
|
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. The software uses a secure password for database access, but this password is shared across instances.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-35567
|
2024-11-21 14:27 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198375
|
5.3 |
MEDIUM
Network
|
mbconnectline helmholz
|
mbconnect24 mymbconnect24 myrex24.virtual myrex24
|
An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. An attacker can read arbitrary JSON files via Local Fil…
|
CWE-706
Use of Incorrectly-Resolved Name or Reference
|
CVE-2020-35566
|
2024-11-21 14:27 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198376
|
9.8 |
CRITICAL
Network
|
mbconnectline
|
mbconnect24 mymbconnect24
|
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. The login pages bruteforce detection is disabled by default.
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2020-35565
|
2024-11-21 14:27 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198377
|
7.5 |
HIGH
Network
|
mbconnectline
|
mbconnect24 mymbconnect24
|
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an outdated and unused component allowing for malicious user input of active code.
|
CWE-74
Injection
|
CVE-2020-35564
|
2024-11-21 14:27 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198378
|
5.4 |
MEDIUM
Network
|
mbconnectline
|
mbconnect24 mymbconnect24
|
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an incomplete XSS filter allowing an attacker to inject crafted malicious code into the page.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35563
|
2024-11-21 14:27 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198379
|
5.3 |
MEDIUM
Network
|
mbconnectline helmholz
|
mbconnect24 mymbconnect24 myrex24.virtual myrex24
|
An issue was discovered MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. There is an SSRF in the HA module allowing an unauthentica…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-35561
|
2024-11-21 14:27 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198380
|
6.1 |
MEDIUM
Network
|
mbconnectline
|
mbconnect24 mymbconnect24
|
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an unauthenticated open redirect in the redirect.php.
|
CWE-601
Open Redirect
|
CVE-2020-35560
|
2024-11-21 14:27 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|