|
249181
|
8.6 |
HIGH
Network
|
honeywell
|
xl_web_ii_controller
|
An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. A user without authenticating can make a directory traversal…
|
CWE-22
Path Traversal
|
CVE-2017-5143
|
2024-11-21 12:27 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249182
|
9.1 |
CRITICAL
Network
|
honeywell
|
xl_web_ii_controller
|
An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. A user with low privileges is able to open and change the pa…
|
CWE-269
Improper Privilege Management
|
CVE-2017-5142
|
2024-11-21 12:27 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249183
|
6.0 |
MEDIUM
Network
|
honeywell
|
xl_web_ii_controller
|
An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. An attacker can establish a new user session, without invali…
|
CWE-384
Session Fixation
|
CVE-2017-5141
|
2024-11-21 12:27 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249184
|
9.8 |
CRITICAL
Network
|
honeywell
|
xl_web_ii_controller
|
An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. Password is stored in clear text.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2017-5140
|
2024-11-21 12:27 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249185
|
9.8 |
CRITICAL
Network
|
honeywell
|
xl_web_ii_controller
|
An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. Any user is able to disclose a password by accessing a speci…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2017-5139
|
2024-11-21 12:27 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249186
|
5.9 |
MEDIUM
Network
|
xabber
|
xabber
|
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This…
|
CWE-20 CWE-346
Improper Input Validation Origin Validation Error
|
CVE-2017-5606
|
2024-11-21 12:27 |
2017-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249187
|
5.9 |
MEDIUM
Network
|
movim
|
movim
|
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This…
|
CWE-20 CWE-346
Improper Input Validation Origin Validation Error
|
CVE-2017-5605
|
2024-11-21 12:27 |
2017-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249188
|
5.9 |
MEDIUM
Network
|
mcabber
|
mcabber
|
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This…
|
CWE-20 CWE-346
Improper Input Validation Origin Validation Error
|
CVE-2017-5604
|
2024-11-21 12:27 |
2017-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249189
|
5.9 |
MEDIUM
Network
|
jitsi
|
jitsi
|
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This…
|
CWE-20 CWE-346
Improper Input Validation Origin Validation Error
|
CVE-2017-5603
|
2024-11-21 12:27 |
2017-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249190
|
5.9 |
MEDIUM
Network
|
jappix_project
|
jappix
|
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This…
|
CWE-20 CWE-346
Improper Input Validation Origin Validation Error
|
CVE-2017-5602
|
2024-11-21 12:27 |
2017-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|