CVE-2019-20465
An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices. It is possible (using TELNET without a password) to control the camera's pan/zoom/tilt functionality. Devamını Oku
An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices. It is possible (using TELNET without a password) to control the camera's pan/zoom/tilt functionality. Devamını Oku
An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices. A local attacker with the "default" account is capable of reading the /etc/passwd file, which contains a weakly hashed root password. By taking this hash and cracking it, the attacker can obtain root rights on the device. Devamını Oku
An issue was discovered in WiZ Colors A60 1.14.0. The device sends unnecessary information to the cloud controller server. Although this information is sent encrypted and has low risk in isolation, it decreases the privacy of the end user. The information sent includes the local IP address being used and the SSID of the Wi-Fi…
An issue was discovered in Luvion Grand Elite 3 Connect through 2020-02-25. Authentication to the device is based on a username and password. The root credentials are the same across all devices of this model. Devamını Oku
An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices. A crash and reboot can be triggered by crafted IP traffic, as demonstrated by the Nikto vulnerability scanner. For example, sending the 111111 string to UDP port 20188 causes a reboot. To deny service for a long time period,…
Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the post content field to /post/editing. Devamını Oku
Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the signature field to /settings/profile. Devamını Oku
Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the post content field to /post/editing. Devamını Oku
Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the signature field to /settings/profile. Devamını Oku
Server Side Request Forgery (SSRF) vulnerability in saveUrlAs function in ImagesService.java in sunkaifei FlyCMS version 20190503. Devamını Oku
Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the post header field to /post/editing. Devamını Oku
Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the nickname field to /settings/profile. Devamını Oku