|
208231
|
4.3 |
MEDIUM
Network
|
glpi-project
|
glpi
|
In GLPI before 9.5.3, ajax/getDropdownValue.php has an Insecure Direct Object Reference (IDOR) vulnerability that allows an attacker to read data from any itemType (e.g., Ticket, Users, etc.).
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2020-27663
|
2024-11-21 14:21 |
2020-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208232
|
4.3 |
MEDIUM
Network
|
glpi-project
|
glpi
|
In GLPI before 9.5.3, ajax/comments.php has an Insecure Direct Object Reference (IDOR) vulnerability that allows an attacker to read data from any database table (e.g., glpi_tickets, glpi_users, etc.…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2020-27662
|
2024-11-21 14:21 |
2020-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208233
|
7.8 |
HIGH
Local
|
trendmicro
|
antivirus\+_security_2020 internet_security_2020 maximum_security_2020 premium_security_2020
|
Trend Micro Security 2020 (Consumer) contains a vulnerability in the installer package that could be exploited by placing a malicious DLL in a non-protected location with high privileges (symlink att…
|
CWE-59
Link Following
|
CVE-2020-27697
|
2024-11-21 14:21 |
2020-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208234
|
7.8 |
HIGH
Local
|
trendmicro
|
antivirus\+_security_2020 internet_security_2020 maximum_security_2020 premium_security_2020
|
Trend Micro Security 2020 (Consumer) contains a vulnerability in the installer package that could be exploited by placing a specific Windows system directory which can lead to obtaining administrativ…
|
NVD-CWE-noinfo
|
CVE-2020-27696
|
2024-11-21 14:21 |
2020-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208235
|
7.8 |
HIGH
Local
|
trendmicro
|
antivirus\+_security_2020 internet_security_2020 maximum_security_2020 premium_security_2020
|
Trend Micro Security 2020 (Consumer) contains a vulnerability in the installer package that could be exploited by placing a malicious DLL in a local directory which can lead to obtaining administrati…
|
CWE-426
Untrusted Search Path
|
CVE-2020-27695
|
2024-11-21 14:21 |
2020-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208236
|
6.5 |
MEDIUM
Network
|
basetech
|
ge-131_bt-1837836_firmware
|
Use of an undocumented user in BASETech GE-131 BT-1837836 firmware 20180921 allows remote attackers to view the video stream.
|
CWE-287
Improper Authentication
|
CVE-2020-27558
|
2024-11-21 14:21 |
2020-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208237
|
5.5 |
MEDIUM
Local
|
basetech
|
ge-131_bt-1837836_firmware
|
Unprotected Storage of Credentials vulnerability in BASETech GE-131 BT-1837836 firmware 20180921 allows local users to gain access to the video streaming username and password via SQLite files contai…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-27557
|
2024-11-21 14:21 |
2020-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208238
|
5.3 |
MEDIUM
Network
|
basetech
|
ge-131_bt-1837836_firmware
|
A predictable device ID in BASETech GE-131 BT-1837836 firmware 20180921 allows unauthenticated remote attackers to connect to the device.
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2020-27556
|
2024-11-21 14:21 |
2020-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208239
|
9.8 |
CRITICAL
Network
|
basetech
|
ge-131_bt-1837836_firmware
|
Use of default credentials for the telnet server in BASETech GE-131 BT-1837836 firmware 20180921 allows remote attackers to execute arbitrary system commands as the root user.
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2020-27555
|
2024-11-21 14:21 |
2020-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208240
|
7.5 |
HIGH
Network
|
basetech
|
ge-131_bt-1837836_firmware
|
Cleartext Transmission of Sensitive Information vulnerability in BASETech GE-131 BT-1837836 firmware 20180921 exists which could leak sensitive information transmitted between the mobile app and the …
|
CWE-319 CWE-522
Cleartext Transmission of Sensitive Information Insufficiently Protected Credentials
|
CVE-2020-27554
|
2024-11-21 14:21 |
2020-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|