|
265511
|
8.2 |
HIGH
Network
|
kabona_ab
|
webdatorcentral
|
An issue was discovered in Kabona AB WebDatorCentral (WDC) application prior to Version 3.4.0. The web server URL inputs are not sanitized correctly, which may allow cross-site scripting vulnerabilit…
|
CWE-79
Cross-site Scripting
|
CVE-2016-8356
|
2024-11-21 11:59 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265512
|
7.0 |
HIGH
Local
|
schneider-electric
|
unity_pro
|
An issue was discovered in Schneider Electric Unity PRO prior to V11.1. Unity projects can be compiled as x86 instructions and loaded onto the PLC Simulator delivered with Unity PRO. These x86 instru…
|
CWE-94
Code Injection
|
CVE-2016-8354
|
2024-11-21 11:59 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265513
|
6.4 |
MEDIUM
Network
|
osisoft
|
pi_web_api_2015_r2
|
An issue was discovered in OSIsoft PI Web API 2015 R2 (Version 1.5.1). There is a weakness in this product that may allow an attacker to access the PI system without the proper permissions.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-8353
|
2024-11-21 11:59 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265514
|
10.0 |
CRITICAL
Network
|
schneider-electric
|
connexium_firmware
|
An issue was discovered in Schneider Electric ConneXium firewalls TCSEFEC23F3F20 all versions, TCSEFEC23F3F21 all versions, TCSEFEC23FCF20 all versions, TCSEFEC23FCF21 all versions, and TCSEFEC2CF3F2…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-8352
|
2024-11-21 11:59 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265515
|
6.3 |
MEDIUM
Network
|
moxa
|
iologik_e1200_series_firmware iologik_e2200_series_firmware
|
An issue was discovered in Moxa ioLogik E1210, firmware Version V2.4 and prior, ioLogik E1211, firmware Version V2.3 and prior, ioLogik E1212, firmware Version V2.4 and prior, ioLogik E1213, firmware…
|
CWE-352
Origin Validation Error
|
CVE-2016-8350
|
2024-11-21 11:59 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265516
|
9.8 |
CRITICAL
Network
|
emerson
|
liebert_sitescan_web
|
An XML External Entity (XXE) issue was discovered in Emerson Liebert SiteScan Web Version 6.5, and prior. An attacker may enter malicious input to Liebert SiteScan through a weakly configured XML par…
|
CWE-611
XXE
|
CVE-2016-8348
|
2024-11-21 11:59 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265517
|
9.8 |
CRITICAL
Network
|
kabona_ab
|
webdatorcentral
|
An issue was discovered in Kabona AB WebDatorCentral (WDC) application prior to Version 3.4.0. WDC does not limit authentication attempts that may allow a brute force attack method.
|
CWE-287
Improper Authentication
|
CVE-2016-8347
|
2024-11-21 11:59 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265518
|
7.5 |
HIGH
Network
|
moxa
|
edr-810_firmware
|
An issue was discovered in Moxa EDR-810 Industrial Secure Router. By accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to access configuration and log fi…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2016-8346
|
2024-11-21 11:59 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265519
|
3.7 |
LOW
Network
|
honeywell
|
experion_process_knowledge_system
|
An issue was discovered in Honeywell Experion Process Knowledge System (PKS) platform: Experion PKS, Release 3xx and prior, Experion PKS, Release 400, Experion PKS, Release 410, Experion PKS, Release…
|
CWE-20
Improper Input Validation
|
CVE-2016-8344
|
2024-11-21 11:59 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265520
|
9.8 |
CRITICAL
Network
|
ecava
|
integraxor
|
An issue was discovered in Ecava IntegraXor Version 5.0.413.0. The Ecava IntegraXor web server has parameters that are vulnerable to SQL injection. If the queries are not sanitized, the host's databa…
|
CWE-89
SQL Injection
|
CVE-2016-8341
|
2024-11-21 11:59 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|