CVE-2020-19616 (mblog)
Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the post header field to /post/editing. Devamını Oku
Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the post header field to /post/editing. Devamını Oku
Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the nickname field to /settings/profile. Devamını Oku
Server Side Request Forgery (SSRF) vulnerability in saveUrlAs function in ImagesService.java in sunkaifei FlyCMS version 20190503. Devamını Oku
Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the post content field to /post/editing. Devamını Oku
Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the signature field to /settings/profile. Devamını Oku
Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the post content field to /post/editing. Devamını Oku
Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the signature field to /settings/profile. Devamını Oku
An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices. A crash and reboot can be triggered by crafted IP traffic, as demonstrated by the Nikto vulnerability scanner. For example, sending the 111111 string to UDP port 20188 causes a reboot. To deny service for a long time period,…
An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices. By default, a mobile application is used to stream over UDP. However, the device offers many more services that also enable streaming. Although the service used by the mobile application requires a password, the other streaming services do not.…
An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices. It is possible (using TELNET without a password) to control the camera's pan/zoom/tilt functionality. Devamını Oku
An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices. A local attacker with the "default" account is capable of reading the /etc/passwd file, which contains a weakly hashed root password. By taking this hash and cracking it, the attacker can obtain root rights on the device. Devamını Oku
An issue was discovered in WiZ Colors A60 1.14.0. The device sends unnecessary information to the cloud controller server. Although this information is sent encrypted and has low risk in isolation, it decreases the privacy of the end user. The information sent includes the local IP address being used and the SSID of the Wi-Fi…