|
199621
|
7.5 |
HIGH
Network
|
dlink
|
dir-880l_firmware
|
The D-Link router DIR-880L 1.07 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an unauthenticated attacker to gain access to the firmware and…
|
CWE-798 CWE-522
Use of Hard-coded Credentials Insufficiently Protected Credentials
|
CVE-2020-29322
|
2024-11-21 14:23 |
2021-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199622
|
7.5 |
HIGH
Network
|
dlink
|
dir-868l_firmware
|
The D-Link router DIR-868L 3.01 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an unauthenticated attacker to gain access to the firmware and…
|
CWE-798 CWE-522
Use of Hard-coded Credentials Insufficiently Protected Credentials
|
CVE-2020-29321
|
2024-11-21 14:23 |
2021-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199623
|
6.5 |
MEDIUM
Network
|
nagios
|
fusion
|
Incorrect Access Control in Nagios Fusion 4.1.8 and earlier allows low-privileged authenticated users to extract passwords used to manage fused servers via the test_server command in ajaxhelper.php.
|
CWE-922
Insecure Storage of Sensitive Information
|
CVE-2020-28911
|
2024-11-21 14:23 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199624
|
9.8 |
CRITICAL
Network
|
nagios
|
nagios_xi
|
Creation of a Temporary Directory with Insecure Permissions in Nagios XI 5.7.5 and earlier allows for Privilege Escalation via creation of symlinks, which are mishandled in getprofile.sh.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-28910
|
2024-11-21 14:23 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199625
|
8.8 |
HIGH
Network
|
nagios
|
fusion
|
Incorrect File Permissions in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to root via modification of scripts. Low-privileges users are able to modify files that can be executed b…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-28909
|
2024-11-21 14:23 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199626
|
9.8 |
CRITICAL
Network
|
nagios
|
fusion
|
Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to nagios.
|
CWE-77
Command Injection
|
CVE-2020-28908
|
2024-11-21 14:23 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199627
|
9.8 |
CRITICAL
Network
|
nagios
|
fusion
|
Incorrect SSL certificate validation in Nagios Fusion 4.1.8 and earlier allows for Escalation of Privileges or Code Execution as root via vectors related to download of an untrusted update package in…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-28907
|
2024-11-21 14:23 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199628
|
8.8 |
HIGH
Network
|
nagios
|
fusion nagios_xi
|
Incorrect File Permissions in Nagios XI 5.7.5 and earlier and Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to root. Low-privileged users are able to modify files that are included …
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-28906
|
2024-11-21 14:23 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199629
|
8.8 |
HIGH
Network
|
nagios
|
fusion
|
Improper Input Validation in Nagios Fusion 4.1.8 and earlier allows an authenticated attacker to execute remote code via table pagination.
|
CWE-94
Code Injection
|
CVE-2020-28905
|
2024-11-21 14:23 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199630
|
9.8 |
CRITICAL
Network
|
nagios
|
fusion
|
Execution with Unnecessary Privileges in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation as nagios via installation of a malicious component containing PHP code.
|
CWE-269
Improper Privilege Management
|
CVE-2020-28904
|
2024-11-21 14:23 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|