|
268431
|
6.1 |
MEDIUM
Network
|
cloudviewnms
|
cloudview_nms
|
CloudView NMS before 2.10a has XSS via SNMP.
|
CWE-79
Cross-site Scripting
|
CVE-2016-5073
|
2024-11-21 11:53 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268432
|
8.8 |
HIGH
Network
|
oxidforge
|
oxid_eshop
|
OXID eShop before 2016-06-13 allows remote attackers to execute arbitrary code via a GET or POST request to the oxuser class. Fixed versions are Enterprise Edition v5.1.12, Enterprise Edition v5.2.9,…
|
CWE-94
Code Injection
|
CVE-2016-5072
|
2024-11-21 11:53 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268433
|
8.8 |
HIGH
Network
|
sierrawireless
|
aleos_firmware
|
Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 execute the management web application as root.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-5071
|
2024-11-21 11:53 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268434
|
9.8 |
CRITICAL
Network
|
sierrawireless
|
aleos_firmware
|
Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 store passwords in cleartext.
|
CWE-255
Credentials Management
|
CVE-2016-5070
|
2024-11-21 11:53 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268435
|
9.8 |
CRITICAL
Network
|
sierrawireless
|
aleos_firmware
|
Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 use guessable session tokens, which are in the URL.
|
CWE-613
Insufficient Session Expiration
|
CVE-2016-5069
|
2024-11-21 11:53 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268436
|
9.8 |
CRITICAL
Network
|
sierrawireless
|
aleos_firmware
|
Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 do not require authentication for Embedded_Ace_Get_Task.cgi requests.
|
CWE-287
Improper Authentication
|
CVE-2016-5068
|
2024-11-21 11:53 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268437
|
8.8 |
HIGH
Network
|
sierrawireless
|
aleos_firmware
|
Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 allow Hayes AT command injection.
|
CWE-77
Command Injection
|
CVE-2016-5067
|
2024-11-21 11:53 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268438
|
9.8 |
CRITICAL
Network
|
sierrawireless
|
aleos_firmware
|
Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 have weak passwords for admin, rauser, sconsole, and user.
|
CWE-255
Credentials Management
|
CVE-2016-5066
|
2024-11-21 11:53 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268439
|
9.8 |
CRITICAL
Network
|
sierrawireless
|
aleos_firmware
|
Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 allow Embedded_Ace_Set_Task.cgi command injection.
|
CWE-77
Command Injection
|
CVE-2016-5065
|
2024-11-21 11:53 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268440
|
6.5 |
MEDIUM
Network
|
osram
|
lightify_pro
|
OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 allows attackers to obtain sensitive information by reading screenshots under /private/var/mobile/Containers/Data/Application.
|
CWE-200
Information Exposure
|
CVE-2016-5059
|
2024-11-21 11:53 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|