|
270991
|
4.3 |
MEDIUM
Network
|
ewon
|
ewon_firmware
|
eWON devices with firmware through 10.1s0 support unspecified GET requests, which might allow remote attackers to obtain sensitive information by reading (1) web-server access logs, (2) web-server Re…
|
CWE-200
Information Exposure
|
CVE-2015-7929
|
2024-11-21 11:37 |
2015-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270992
|
8.5 |
HIGH
Network
|
ewon
|
ewon_firmware
|
eWON devices with firmware before 10.1s0 do not have an off autocomplete attribute for a password field, which makes it easier for remote attackers to obtain access by leveraging an unattended workst…
|
CWE-200
Information Exposure
|
CVE-2015-7928
|
2024-11-21 11:37 |
2015-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270993
|
6.1 |
MEDIUM
Network
|
ewon
|
ewon_firmware
|
Cross-site scripting (XSS) vulnerability on eWON devices with firmware through 10.1s0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2015-7927
|
2024-11-21 11:37 |
2015-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270994
|
9.9 |
CRITICAL
Network
|
ewon
|
ewon_firmware
|
eWON devices with firmware before 10.1s0 omit RBAC for I/O server information and status requests, which allows remote attackers to obtain sensitive information via an unspecified URL.
|
CWE-200
Information Exposure
|
CVE-2015-7926
|
2024-11-21 11:37 |
2015-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270995
|
8.0 |
HIGH
Network
|
ewon
|
ewon_firmware
|
Cross-site request forgery (CSRF) vulnerability on eWON devices with firmware through 10.1s0 allows remote attackers to hijack the authentication of administrators for requests that trigger firmware …
|
CWE-352
Origin Validation Error
|
CVE-2015-7925
|
2024-11-21 11:37 |
2015-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270996
|
8.8 |
HIGH
Network
|
ewon
|
ewon_firmware
|
eWON devices with firmware before 10.1s0 do not trigger the discarding of browser session data in response to a log-off action, which makes it easier for remote attackers to obtain access by leveragi…
|
NVD-CWE-Other
|
CVE-2015-7924
|
2024-11-21 11:37 |
2015-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270997
|
7.5 |
HIGH
Network
|
motorola
|
moscad_ip_gateway_firmware
|
Cross-site request forgery (CSRF) vulnerability in Motorola Solutions MOSCAD IP Gateway allows remote attackers to hijack the authentication of administrators for requests that modify a password.
|
CWE-352
Origin Validation Error
|
CVE-2015-7936
|
2024-11-21 11:37 |
2015-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270998
|
7.5 |
HIGH
Network
|
motorola
|
moscad_ip_gateway_firmware
|
Motorola Solutions MOSCAD IP Gateway allows remote attackers to read arbitrary files via unspecified vectors.
|
CWE-200
Information Exposure
|
CVE-2015-7935
|
2024-11-21 11:37 |
2015-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270999
|
7.2 |
HIGH
Local
|
opcsystems
|
opc_systems.net
|
Untrusted search path vulnerability in Open Automation OPC Systems.NET 8.00.0023 and earlier allows local users to gain privileges via a Trojan horse DLL in an unspecified directory.
|
NVD-CWE-Other
|
CVE-2015-7917
|
2024-11-21 11:37 |
2015-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271000
|
9.1 |
CRITICAL
Network
|
saia_burgess_controls
|
pcd7.d4xxv_vga_mb_firmware pcd7.d4xxd_firmware pcd3.mxxx0_firmware pcd7.d4xxd_svga_mb_firmware pcd3.t666_firmware pcd1.m2xx0_firmware pcd3.mxx60_firmware pcd3.t665_firmware pc…
|
Saia Burgess PCD1.M0xx0, PCD1.M2xx0, PCD2.M5xx0, PCD3.Mxx60, PCD3.Mxxx0, PCD7.D4xxD, PCD7.D4xxV, PCD7.D4xxWTPF, and PCD7.D4xxxT5F devices before 1.24.50 and PCD3.T665 and PCD3.T666 devices before 1.2…
|
CWE-255
Credentials Management
|
CVE-2015-7911
|
2024-11-21 11:37 |
2015-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|