|
222981
|
4.3 |
MEDIUM
Network
|
hitachienergy
|
esoms
|
For ABB eSOMS versions 4.0 to 6.0.3, HTTPS responses contain comments with sensitive information about the application. An attacker might use this detail information to specifically craft the attack.
|
CWE-200
Information Exposure
|
CVE-2019-19091
|
2024-11-21 13:34 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222982
|
3.5 |
LOW
Network
|
hitachienergy
|
esoms
|
For ABB eSOMS versions 4.0 to 6.0.2, the Secure Flag is not set in the HTTP response header. Unencrypted connections might access the cookie information, thus making it susceptible to eavesdropping.
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2019-19090
|
2024-11-21 13:34 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222983
|
6.1 |
MEDIUM
Network
|
hitachienergy
|
esoms
|
For ABB eSOMS versions 4.0 to 6.0.3, the X-Content-Type-Options Header is missing in the HTTP response, potentially causing the response body to be interpreted and displayed as different content type…
|
CWE-94 CWE-436
Code Injection Interpretation Conflict
|
CVE-2019-19089
|
2024-11-21 13:34 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222984
|
8.1 |
HIGH
Network
|
tribalgroup
|
sits\
|
An authentication bypass vulnerability is present in the standalone SITS:Vision 9.7.0 component of Tribal SITS in its default configuration, related to unencrypted communications sent by the client e…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-19127
|
2024-11-21 13:34 |
2020-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222985
|
7.2 |
HIGH
Network
|
zohocorp
|
manageengine_assetexplorer
|
Zoho ManageEngine Asset Explorer 6.5 does not validate the System Center Configuration Manager (SCCM) database username when dynamically generating a command to schedule scans for SCCM. This allows a…
|
CWE-78
OS Command
|
CVE-2019-19034
|
2024-11-21 13:34 |
2020-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222986
|
7.5 |
HIGH
Network
|
xmidt
|
cjwt
|
Xmidt cjwt through 1.0.1 before 2019-11-25 maps unsupported algorithms to alg=none, which sometimes leads to untrusted accidental JWT acceptance.
|
CWE-670
Always-Incorrect Control Flow Implementation
|
CVE-2019-19324
|
2024-11-21 13:34 |
2020-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222987
|
9.8 |
CRITICAL
Network
|
tellabs
|
optical_line_terminal_1150_firmware
|
Tellabs Optical Line Terminal (OLT) 1150 devices allow Remote Command Execution via the -l option to TELNET or SSH. Tellabs has addressed this issue in the SR30.1 and SR31.1 release on February 18, 2…
|
CWE-78
OS Command
|
CVE-2019-19148
|
2024-11-21 13:34 |
2020-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222988
|
7.8 |
HIGH
Local
|
redhat
|
openshift
|
A vulnerability was found in all openshift/mediawiki-apb 4.x.x versions prior to 4.3.0, where an insecure modification vulnerability in the /etc/passwd file was found in the container openshift/media…
|
-
|
CVE-2019-19345
|
2024-11-21 13:34 |
2020-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222989
|
8.8 |
HIGH
Network
|
centreon
|
centreon
|
Command Injection in minPlayCommand.php in Centreon (19.04.4 and below) allows an attacker to achieve command injection via a plugin test.
|
CWE-78
OS Command
|
CVE-2019-19487
|
2024-11-21 13:34 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222990
|
6.5 |
MEDIUM
Network
|
centreon
|
centreon
|
Local File Inclusion in minPlayCommand.php in Centreon (19.04.4 and below) allows an attacker to traverse paths via a plugin test.
|
CWE-22
Path Traversal
|
CVE-2019-19486
|
2024-11-21 13:34 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|