|
210761
|
9.8 |
CRITICAL
Network
|
gogogate
|
ismartgate_pro_firmware
|
ismartgate PRO 1.5.9 is vulnerable to malicious file uploads via the form for uploading sounds to garage doors. The magic bytes for WAV must be used.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-12843
|
2024-11-21 14:00 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210762
|
9.8 |
CRITICAL
Network
|
gogogate
|
ismartgate_pro_firmware
|
ismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/checkUserExpirationDate.php.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-12842
|
2024-11-21 14:00 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210763
|
6.5 |
MEDIUM
Network
|
gogogate
|
ismartgate_pro_firmware
|
ismartgate PRO 1.5.9 is vulnerable to CSRF that allows remote attackers to upload imae files via /index.php
|
CWE-352
Origin Validation Error
|
CVE-2020-12841
|
2024-11-21 14:00 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210764
|
6.5 |
MEDIUM
Network
|
gogogate
|
ismartgate_pro_firmware
|
ismartgate PRO 1.5.9 is vulnerable to CSRF that allows remote attackers to upload sound files via /index.php
|
CWE-352
Origin Validation Error
|
CVE-2020-12840
|
2024-11-21 14:00 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210765
|
9.8 |
CRITICAL
Network
|
gogogate
|
ismartgate_pro_firmware
|
ismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/checkExpirationDate.php.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-12839
|
2024-11-21 14:00 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210766
|
9.8 |
CRITICAL
Network
|
gogogate
|
ismartgate_pro_firmware
|
ismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/mailAdmin.php.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-12838
|
2024-11-21 14:00 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210767
|
7.5 |
HIGH
Network
|
gogogate
|
ismartgate_pro_firmware
|
ismartgate PRO 1.5.9 is vulnerable to malicious file uploads via the form for uploading images to garage doors. The magic bytes of PNG must be used.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-12837
|
2024-11-21 14:00 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210768
|
5.3 |
MEDIUM
Network
|
fortinet
|
fortios
|
An insufficient logging vulnerability in FortiGate before 6.4.1 may allow the traffic from an unauthenticated attacker to Fortinet owned IP addresses to go unnoticed.
|
NVD-CWE-Other
|
CVE-2020-12818
|
2024-11-21 14:00 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210769
|
8.8 |
HIGH
Network
|
fortinet
|
fortitester fortianalyzer
|
An improper neutralization of input vulnerability in FortiAnalyzer before 6.4.1 and 6.2.5 may allow a remote authenticated attacker to inject script related HTML tags via Name parameter of Storage Co…
|
CWE-79
Cross-site Scripting
|
CVE-2020-12817
|
2024-11-21 14:00 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210770
|
6.1 |
MEDIUM
Network
|
fortinet
|
fortinac
|
An improper neutralization of input vulnerability in FortiNAC before 8.7.2 may allow a remote authenticated attacker to perform a stored cross site scripting attack (XSS) via the UserID of Admin User…
|
CWE-79
Cross-site Scripting
|
CVE-2020-12816
|
2024-11-21 14:00 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|