|
210361
|
8.8 |
HIGH
Network
|
rconfig
|
rconfig
|
rConfig 3.9.4 is vulnerable to remote code execution due to improper validation in the file upload functionality. vendor.crud.php accepts a file upload by checking content-type without considering th…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-12255
|
2024-11-21 13:59 |
2020-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210362
|
9.1 |
CRITICAL
Network
|
rconfig
|
rconfig
|
rConfig 3.9.4 is vulnerable to session fixation because session expiry and randomization are mishandled. The application can reuse a session via PHPSESSID. Also, an attacker can exploit this vulnerab…
|
CWE-384
Session Fixation
|
CVE-2020-12258
|
2024-11-21 13:59 |
2020-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210363
|
8.8 |
HIGH
Network
|
rconfig
|
rconfig
|
rConfig 3.9.4 is vulnerable to cross-site request forgery (CSRF) because it lacks implementation of CSRF protection such as a CSRF token. An attacker can leverage this vulnerability by creating a for…
|
CWE-352
Origin Validation Error
|
CVE-2020-12257
|
2024-11-21 13:59 |
2020-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210364
|
5.4 |
MEDIUM
Network
|
rconfig
|
rconfig
|
rConfig 3.9.4 is vulnerable to reflected XSS. The configDevice.php file improperly validates user input. An attacker can exploit this vulnerability by crafting arbitrary JavaScript in the rid GET par…
|
CWE-79
Cross-site Scripting
|
CVE-2020-12259
|
2024-11-21 13:59 |
2020-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210365
|
9.8 |
CRITICAL
Network
|
vandyke
|
securecrt
|
SecureCRT before 8.7.2 allows remote attackers to execute arbitrary code via an Integer Overflow and a Buffer Overflow because a banner can trigger a line number to CSI functions that exceeds INT_MAX.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-12651
|
2024-11-21 13:59 |
2020-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210366
|
6.5 |
MEDIUM
Network
|
codesys
|
development_system control_for_beaglebone control_for_empc-a\/imx6 control_for_iot2000 control_for_pfc100 control_for_pfc200 control_for_plcnext control_for_raspberry_pi contr…
|
An issue was discovered in CODESYS Development System before 3.5.16.0. CODESYS WebVisu and CODESYS Remote TargetVisu are susceptible to privilege escalation.
|
NVD-CWE-noinfo
|
CVE-2020-12068
|
2024-11-21 13:59 |
2020-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210367
|
5.7 |
MEDIUM
Network
|
opto22
|
softpac_project
|
Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC’s firmware files’ signatures are not verified upon firmware update. This allows an attacker to replace legitimate firmware files with malicious …
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2020-12046
|
2024-11-21 13:59 |
2020-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210368
|
6.5 |
MEDIUM
Network
|
opto22
|
softpac_project
|
Opto 22 SoftPAC Project Version 9.6 and prior. Paths specified within the zip files used to update the SoftPAC firmware are not sanitized. As a result, an attacker with user privileges can gain arbit…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2020-12042
|
2024-11-21 13:59 |
2020-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210369
|
9.8 |
CRITICAL
Network
|
apache oracle
|
camel flexcube_private_banking enterprise_manager_base_platform communications_diameter_signaling_router
|
Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade t…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-11973
|
2024-11-21 13:59 |
2020-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210370
|
9.8 |
CRITICAL
Network
|
apache oracle
|
camel flexcube_private_banking enterprise_manager_base_platform communications_diameter_signaling_router
|
Apache Camel RabbitMQ enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrad…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-11972
|
2024-11-21 13:59 |
2020-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|