|
246381
|
7.8 |
HIGH
Local
|
hidglobal
|
easylobby_solo
|
EasyLobby Solo contains default administrative credentials. An attacker could exploit this vulnerability to gain full access to the application.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2018-17492
|
2024-11-21 12:54 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246382
|
7.8 |
HIGH
Local
|
hidglobal
|
easylobby_solo
|
EasyLobby Solo could allow a local attacker to gain elevated privileges on the system. By visiting the kiosk and typing "esc" to exit the program, an attacker could exploit this vulnerability to perf…
|
CWE-862
Missing Authorization
|
CVE-2018-17491
|
2024-11-21 12:54 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246383
|
7.1 |
HIGH
Local
|
hidglobal
|
easylobby_solo
|
EasyLobby Solo is vulnerable to a denial of service. By visiting the kiosk and accessing the task manager, a local attacker could exploit this vulnerability to kill the process or launch new processe…
|
CWE-862
Missing Authorization
|
CVE-2018-17490
|
2024-11-21 12:54 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246384
|
5.5 |
MEDIUM
Local
|
hidglobal
|
easylobby_solo
|
EasyLobby Solo could allow a local attacker to obtain sensitive information, caused by the storing of the social security number in plaintext. By visiting the kiosk and viewing the Visitor table of t…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2018-17489
|
2024-11-21 12:54 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246385
|
7.8 |
HIGH
Local
|
jollytech
|
lobby_track
|
Lobby Track Desktop could allow a local attacker to gain elevated privileges on the system, caused by an error in the printer dialog. By visiting the kiosk and accessing the print badge screen, an at…
|
NVD-CWE-noinfo
|
CVE-2018-17488
|
2024-11-21 12:54 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246386
|
7.8 |
HIGH
Local
|
jollytech
|
lobby_track
|
Lobby Track Desktop could allow a local attacker to gain elevated privileges on the system, caused by an error in the printer dialog. By visiting the kiosk and signing in as a visitor, an attacker co…
|
NVD-CWE-noinfo
|
CVE-2018-17487
|
2024-11-21 12:54 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246387
|
5.5 |
MEDIUM
Local
|
jollytech
|
lobby_track
|
Lobby Track Desktop could allow a local attacker to bypass security restrictions, caused by an error in the find visitor function while in kiosk mode. By visiting the kiosk and selecting find visitor…
|
NVD-CWE-noinfo
|
CVE-2018-17486
|
2024-11-21 12:54 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246388
|
7.8 |
HIGH
Local
|
jollytech
|
lobby_track
|
Lobby Track Desktop contains default administrative credentials. An attacker could exploit this vulnerability to gain full access to the application.
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2018-17485
|
2024-11-21 12:54 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246389
|
7.1 |
HIGH
Local
|
jollytech
|
lobby_track
|
Lobby Track Desktop could allow a local attacker to obtain sensitive information, caused by an error in Sample Database.mdb database while in kiosk mode. By using attack vectors outlined in kiosk bre…
|
CWE-200
Information Exposure
|
CVE-2018-17484
|
2024-11-21 12:54 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246390
|
5.5 |
MEDIUM
Local
|
jollytech
|
lobby_track
|
Lobby Track Desktop could allow a local attacker to obtain sensitive information, caused by an error in Reports while in kiosk mode. By visiting the kiosk and viewing the driver's license column, an …
|
CWE-200
Information Exposure
|
CVE-2018-17483
|
2024-11-21 12:54 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|