Security
Headlines
HeadlinesLatestCVEs

Tag

#windows

Ewon Cosy+ Command Injection

The Ewon Cosy+ is a VPN gateway used for remote access and maintenance in industrial environments. Due to improper neutralization of parameters read from a user-controlled configuration file, an authenticated attacker is able to inject and execute OS commands on the device.

Packet Storm
#vulnerability#web#mac#windows#js#pdf#auth#telnet
Ewon Cosy+ Password Disclosure

The Ewon Cosy+ is a VPN gateway used for remote access and maintenance in industrial environments. The credentials used for the basic authentication against the web interface of Cosy+ are stored in the cookie "credentials" after a successful login. An attacker with access to a victim's browser is able to retrieve the administrative password of Cosy+.

Ewon Cosy+ Improper Neutralization / Cross Site Scripting

The Ewon Cosy+ is a VPN gateway used for remote access and maintenance in industrial environments. If login against the FTP service of the Cosy+ fails, the submitted username is saved in a log. This log is included in the Cosy+ web interface without neutralizing the content. As a result, an unauthenticated attacker is able to inject HTML/JavaScript code via the username of an FTP login attempt.

Lawyer CMS 1.6 Insecure Settings

Lawyer CMS version 1.6 suffers from an ignored default credential vulnerability.

Karya Online Shopping Portal 2.0 SQL Injection

Karya Online Shopping Portal version 2.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

JobSeeker CMS 1.5 Insecure Settings

JobSeeker CMS version 1.5 suffers from an ignored default credential vulnerability.

Hotel Management System 1.0 Cross Site Request Forgery

Hotel Management System version 1.0 suffers from a cross site request forgery vulnerability.