|
213631
|
7.5 |
HIGH
Network
|
cipplanner
|
cipace
|
An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request and get the content of ETL Processes running on the server.
|
NVD-CWE-noinfo
|
CVE-2020-11587
|
2024-11-21 13:58 |
2020-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213632
|
9.8 |
CRITICAL
Network
|
cipplanner
|
cipace
|
An XXE issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request that contains malicious XML DTD data.
|
CWE-611
XXE
|
CVE-2020-11586
|
2024-11-21 13:58 |
2020-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213633
|
7.5 |
HIGH
Network
|
cipplanner
|
cipace
|
An issue was discovered in CIPPlanner CIPAce 6.80 Build 2016031401. GetDistributedPOP3 allows attackers to obtain the username and password of the SMTP user.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-11599
|
2024-11-21 13:58 |
2020-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213634
|
9.8 |
CRITICAL
Network
|
cipplanner
|
cipace
|
An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. Upload.ashx allows remote attackers to execute arbitrary code by uploading and executing an ASHX file.
|
CWE-306 CWE-434
Missing Authentication for Critical Function Unrestricted Upload of File with Dangerous Type
|
CVE-2020-11598
|
2024-11-21 13:58 |
2020-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213635
|
9.8 |
CRITICAL
Network
|
cipplanner
|
cipace
|
An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP POST request and inject SQL statements in the user context of the db owner.
|
CWE-89
SQL Injection
|
CVE-2020-11597
|
2024-11-21 13:58 |
2020-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213636
|
7.5 |
HIGH
Network
|
cipplanner
|
cipace
|
A Directory Traversal issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make HTTP GET requests to a certain URL and obtain information about what files a…
|
CWE-22
Path Traversal
|
CVE-2020-11596
|
2024-11-21 13:58 |
2020-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213637
|
7.5 |
HIGH
Network
|
cipplanner
|
cipace
|
An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request and obtain the upload folder path that includes the hostname in a UNC path.
|
NVD-CWE-noinfo
|
CVE-2020-11595
|
2024-11-21 13:58 |
2020-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213638
|
7.5 |
HIGH
Network
|
cipplanner
|
cipace
|
An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request that causes a stack error to be shown providing the full file path.
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2020-11594
|
2024-11-21 13:58 |
2020-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213639
|
7.5 |
HIGH
Network
|
cipplanner
|
cipace
|
An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP POST request with injected HTML data that is later leveraged to send emails from a cust…
|
CWE-74
Injection
|
CVE-2020-11593
|
2024-11-21 13:58 |
2020-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213640
|
7.5 |
HIGH
Network
|
cipplanner
|
cipace
|
An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request and get the columns of a specific table within the CIP database.
|
NVD-CWE-noinfo
|
CVE-2020-11592
|
2024-11-21 13:58 |
2020-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|