|
265931
|
7.5 |
HIGH
Network
|
imagely
|
nextgen_gallery
|
The Imagely NextGen Gallery plugin for Wordpress prior to version 2.1.57 does not properly validate user input in the cssfile parameter of a HTTP POST request, which may allow an authenticated user t…
|
CWE-20
Improper Input Validation
|
CVE-2016-6565
|
2024-11-21 11:56 |
2018-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265932
|
7.5 |
HIGH
Adjacent
|
mitel
|
shortel_mobility_client
|
On iOS and Android devices, the ShoreTel Mobility Client app version 9.1.3.109 fails to properly validate SSL certificates provided by HTTPS connections, which means that an attacker in the position …
|
CWE-295
Improper Certificate Validation
|
CVE-2016-6562
|
2024-11-21 11:56 |
2018-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265933
|
9.8 |
CRITICAL
Network
|
synology
|
ds107_firmware ds213_firmware ds116_firmware
|
Synology NAS servers DS107, firmware version 3.1-1639 and prior, and DS116, DS213, firmware versions prior to 5.2-5644-1, use non-random default credentials of: guest:(blank) and admin:(blank) . A re…
|
CWE-255
Credentials Management
|
CVE-2016-6554
|
2024-11-21 11:56 |
2018-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265934
|
9.8 |
CRITICAL
Network
|
nuuo
|
nt-4040_titan_firmware
|
Nuuo NT-4040 Titan, firmware NT-4040_01.07.0000.0015_1120, uses non-random default credentials of: admin:admin and localdisplay:111111. A remote network attacker can gain privileged access to a vulne…
|
CWE-255
Credentials Management
|
CVE-2016-6553
|
2024-11-21 11:56 |
2018-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265935
|
9.8 |
CRITICAL
Network
|
greenpacket
|
dx-350_firmware
|
Green Packet DX-350 uses non-random default credentials of: root:wimax. A remote network attacker can gain privileged access to a vulnerable device.
|
CWE-255
Credentials Management
|
CVE-2016-6552
|
2024-11-21 11:56 |
2018-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265936
|
9.8 |
CRITICAL
Network
|
intelliantech
|
v60_firmware v60ka_firmware v65_firmware v80g_firmware t80w_firmware t80q_firmware t100w_firmware t100q_firmware t110w_firmware t110q_firmware t130w_firmware t130q_fi…
|
Intellian Satellite TV antennas t-Series and v-Series, firmware version 1.07, uses non-random default credentials of: ftp/ftp or intellian:12345678. A remote network attacker can gain elevated access…
|
CWE-255
Credentials Management
|
CVE-2016-6551
|
2024-11-21 11:56 |
2018-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265937
|
4.3 |
MEDIUM
Adjacent
|
nutspace
|
nut_mobile
|
The Zizai Tech Nut device allows unauthenticated Bluetooth pairing, which enables unauthenticated connected applications to write data to the device name attribute.
|
CWE-287
Improper Authentication
|
CVE-2016-6549
|
2024-11-21 11:56 |
2018-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265938
|
9.8 |
CRITICAL
Network
|
nutspace
|
nut_mobile
|
The Zizai Tech Nut mobile app makes requests via HTTP instead of HTTPS. These requests contain the user's authenticated session token with the URL. An attacker can capture these requests and reuse th…
|
CWE-200
Information Exposure
|
CVE-2016-6548
|
2024-11-21 11:56 |
2018-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265939
|
7.8 |
HIGH
Local
|
nutspace
|
nut_mobile
|
The Zizai Tech Nut mobile app stores the account password used to authenticate to the cloud API in cleartext in the cache.db file.
|
CWE-255 CWE-200
Credentials Management Information Exposure
|
CVE-2016-6547
|
2024-11-21 11:56 |
2018-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265940
|
7.8 |
HIGH
Local
|
kkmcn
|
itrackeasy
|
The iTrack Easy mobile application stores the account password used to authenticate to the cloud API in base64-encoding in the cache.db file. The base64 encoding format is considered equivalent to cl…
|
CWE-255 CWE-200
Credentials Management Information Exposure
|
CVE-2016-6546
|
2024-11-21 11:56 |
2018-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|