|
247751
|
6.1 |
MEDIUM
Network
|
schneider_electric
|
homelynk_controller_lss100100_firmware
|
An issue was discovered in Schneider Electric homeLYnk Controller, LSS100100, all versions prior to V1.5.0. The homeLYnk controller is susceptible to a cross-site scripting attack. User inputs can be…
|
CWE-79
Cross-site Scripting
|
CVE-2017-5157
|
2024-11-21 12:27 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247752
|
7.3 |
HIGH
Network
|
schneider-electric
|
wonderware_historian
|
An issue was discovered in Schneider Electric Wonderware Historian 2014 R2 SP1 P01 and earlier. Wonderware Historian creates logins with default passwords, which can allow a malicious entity to compr…
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2017-5155
|
2024-11-21 12:27 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247753
|
9.8 |
CRITICAL
Network
|
advantech
|
webaccess
|
An issue was discovered in Advantech WebAccess Version 8.1. To be able to exploit the SQL injection vulnerability, an attacker must supply malformed input to the WebAccess software. Successful attack…
|
CWE-89
SQL Injection
|
CVE-2017-5154
|
2024-11-21 12:27 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247754
|
7.8 |
HIGH
Local
|
osisoft
|
pi_coresight pi_web_api
|
An issue was discovered in OSIsoft PI Coresight 2016 R2 and earlier versions, and PI Web API 2016 R2 when deployed using the PI AF Services 2016 R2 integrated install kit. An information exposure thr…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2017-5153
|
2024-11-21 12:27 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247755
|
9.1 |
CRITICAL
Network
|
advantech
|
webaccess
|
An issue was discovered in Advantech WebAccess Version 8.1. By accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to access pages unrestricted (AUTHENTICA…
|
CWE-287
Improper Authentication
|
CVE-2017-5152
|
2024-11-21 12:27 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247756
|
7.3 |
HIGH
Network
|
panasonic
|
video_insight_web_client
|
An issue was discovered in VideoInsight Web Client Version 6.3.5.11 and previous versions. A SQL Injection vulnerability has been identified, which may allow remote code execution.
|
CWE-89
SQL Injection
|
CVE-2017-5151
|
2024-11-21 12:27 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247757
|
7.5 |
HIGH
Network
|
carlosgavazzi
|
vmu-c_em_firmware vmu-c_pv_firmware
|
An issue was discovered in Carlo Gavazzi VMU-C EM prior to firmware Version A11_U05, and VMU-C PV prior to firmware Version A17. Sensitive information is stored in clear-text.
|
CWE-200
Information Exposure
|
CVE-2017-5146
|
2024-11-21 12:27 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247758
|
10.0 |
CRITICAL
Network
|
carlosgavazzi
|
vmu-c_em_firmware vmu-c_pv_firmware
|
An issue was discovered in Carlo Gavazzi VMU-C EM prior to firmware Version A11_U05, and VMU-C PV prior to firmware Version A17. Successful exploitation of this CROSS-SITE REQUEST FORGERY (CSRF) vuln…
|
CWE-352
Origin Validation Error
|
CVE-2017-5145
|
2024-11-21 12:27 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247759
|
9.8 |
CRITICAL
Network
|
carlosgavazzi
|
vmu-c_em_firmware vmu-c_pv_firmware
|
An issue was discovered in Carlo Gavazzi VMU-C EM prior to firmware Version A11_U05, and VMU-C PV prior to firmware Version A17. The access control flaw allows access to most application functions wi…
|
NVD-CWE-noinfo
|
CVE-2017-5144
|
2024-11-21 12:27 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247760
|
8.6 |
HIGH
Network
|
honeywell
|
xl_web_ii_controller
|
An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. A user without authenticating can make a directory traversal…
|
CWE-22
Path Traversal
|
CVE-2017-5143
|
2024-11-21 12:27 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|