|
222091
|
7.5 |
HIGH
Network
|
honeywell
|
h2w2pc1m_firmware h2w2per3_firmware h2w4per3_firmware h4w2per2_firmware h4w2per3_firmware h4w4per2_firmware h4w4per3_firmware h4w8pr2_firmware hbd2per1_firmware hbw2per1_fi…
|
Honeywell equIP series IP cameras Multiple equIP Series Cameras, A vulnerability exists in the affected products where a specially crafted HTTP packet request could result in a denial of service.
|
CWE-20
Improper Input Validation
|
CVE-2019-18228
|
2024-11-21 13:32 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222092
|
9.8 |
CRITICAL
Network
|
honeywell
|
h2w2pc1m_firmware h2w2per3_firmware h2w4per3_firmware h4w2per2_firmware h4w2per3_firmware h4w4per2_firmware h4w4per3_firmware h4w8pr2_firmware hbd2per1_firmware hbw2per1_fi…
|
Honeywell equIP series and Performance series IP cameras and recorders, A vulnerability exists in the affected products where IP cameras and recorders have a potential replay attack vulnerability as …
|
CWE-294
Authentication Bypass by Capture-replay
|
CVE-2019-18226
|
2024-11-21 13:32 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222093
|
6.1 |
MEDIUM
Network
|
apakgroup
|
wholesale_floorplanning_finance
|
In Apak Wholesale Floorplanning Finance 6.31.8.3 and 6.31.8.5, an attacker can send an authenticated POST request with a malicious payload to /WFS/agreementView.faces allowing a stored XSS via the ma…
|
CWE-79
Cross-site Scripting
|
CVE-2019-17551
|
2024-11-21 13:32 |
2019-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222094
|
6.5 |
MEDIUM
Network
|
clipsoft
|
rexpert
|
ClipSoft REXPERT 1.0.0.527 and earlier version allows remote attacker to arbitrary file deletion by issuing a HTTP GET request with a specially crafted parameter. User interaction is required to expl…
|
NVD-CWE-noinfo
|
CVE-2019-17326
|
2024-11-21 13:32 |
2019-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222095
|
6.5 |
MEDIUM
Network
|
clipsoft
|
rexpert
|
ClipSoft REXPERT 1.0.0.527 and earlier version allows remote attacker to upload arbitrary local file via the ActiveX method in RexViewerCtrl30.ocx. That could lead to disclosure of sensitive informat…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-17325
|
2024-11-21 13:32 |
2019-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222096
|
6.5 |
MEDIUM
Network
|
clipsoft
|
rexpert
|
ClipSoft REXPERT 1.0.0.527 and earlier version allows directory traversal by issuing a special HTTP POST request with ../ characters. This could lead to create malicious HTML file, because they can i…
|
CWE-22
Path Traversal
|
CVE-2019-17324
|
2024-11-21 13:32 |
2019-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222097
|
8.8 |
HIGH
Network
|
clipsoft
|
rexpert
|
ClipSoft REXPERT 1.0.0.527 and earlier version allows arbitrary file creation and execution via report print function of rexpert viewer with modified XML document. User interaction is required to exp…
|
CWE-91
Blind XPath Injection
|
CVE-2019-17323
|
2024-11-21 13:32 |
2019-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222098
|
6.5 |
MEDIUM
Network
|
clipsoft
|
rexpert
|
ClipSoft REXPERT 1.0.0.527 and earlier version allows arbitrary file creation via a POST request with the parameter set to the file path to be written. This can be an executable file that is written …
|
CWE-22
Path Traversal
|
CVE-2019-17322
|
2024-11-21 13:32 |
2019-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222099
|
5.3 |
MEDIUM
Network
|
clipsoft
|
rexpert
|
ClipSoft REXPERT 1.0.0.527 and earlier version have an information disclosure issue. When requesting web page associated with session, could leak username via session file path of HTTP response data.…
|
CWE-200
Information Exposure
|
CVE-2019-17321
|
2024-11-21 13:32 |
2019-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222100
|
5.4 |
MEDIUM
Network
|
zucchetti
|
infobusiness
|
In Zucchetti InfoBusiness before and including 4.4.1, an authenticated user can inject client-side code due to improper validation of the Title field in the InfoBusiness Web Component. The payload wi…
|
CWE-79
Cross-site Scripting
|
CVE-2019-18207
|
2024-11-21 13:32 |
2019-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|