‼ CVE-2020-35564 ‼
📖 Read
via "National Vulnerability Database".
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an outdated and unused component allowing for malicious user input of active code.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-35567 ‼
📖 Read
via "National Vulnerability Database".
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. The software uses a secure password for database access, but this password is shared across instances.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-35565 ‼
📖 Read
via "National Vulnerability Database".
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. The login pages bruteforce detection is disabled by default.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-29023 ‼
📖 Read
via "National Vulnerability Database".
Improper Encoding or Escaping of Output from CSV Report Generator of Secomea GateManager allows an authenticated administrator to generate a CSV file that may run arbitrary commands on a victim's computer when opened in a spreadsheet program (like Excel). This issue affects: Secomea GateManager all versions prior to 9.3.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-35563 ‼
📖 Read
via "National Vulnerability Database".
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an incomplete XSS filter allowing an attacker to inject crafted malicious code into the page.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-29027 ‼
📖 Read
via "National Vulnerability Database".
Cross-site Scripting (XSS) vulnerability in GUI of Secomea SiteManager could allow an attacker to cause an XSS Attack. This issue affects: Secomea SiteManager all versions prior to 9.3.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-35570 ‼
📖 Read
via "National Vulnerability Database".
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. An unauthenticated attacker is able to access files (that should have been restricted) via forceful browsing.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-35560 ‼
📖 Read
via "National Vulnerability Database".
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an unauthenticated open redirect in the redirect.php.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-29024 ‼
📖 Read
via "National Vulnerability Database".
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in (GTA) GoToAppliance of Secomea GateManager could allow an attacker to gain access to sensitive cookies. This issue affects: Secomea GateManager all versions prior to 9.3.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-29025 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability in SiteManager-Embedded (SM-E) Web server which may allow attacker to construct a URL that if visited by another application user, will cause JavaScript code supplied by the attacker to execute within the user's browser in the context of that user's session with the application. This issue affects all versions and variants of SM-E prior to version 9.3📖 Read
via "National Vulnerability Database".
‼ CVE-2020-35569 ‼
📖 Read
via "National Vulnerability Database".
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is a self XSS issue with a crafted cookie in the login page.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-27232 ‼
📖 Read
via "National Vulnerability Database".
The RTSPLive555.dll ActiveX control in Pelco Digital Sentry Server 7.18.72.11464 has a SetCameraConnectionParameter stack-based buffer overflow. This can be exploited by a remote attacker to potentially execute arbitrary attacker-supplied code. The victim would have to visit a malicious webpage using Internet Explorer where the exploit could be triggered.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-35561 ‼
📖 Read
via "National Vulnerability Database".
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an SSRF in the HA module allowing an unauthenticated attacker to scan for open ports.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-35559 ‼
📖 Read
via "National Vulnerability Database".
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an unused function that allows an authenticated attacker to use up all available IPs of an account and thus not allow creation of new devices and users.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-35557 ‼
📖 Read
via "National Vulnerability Database".
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. Improper use of access validation allows a logged in user to interact with devices in the account he should not have access to.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-25648 ‼
📖 Read
via "National Vulnerability Database".
Mobile application "Testes de Codigo" 11.4 and prior allows an attacker to gain access to the administrative interface and premium features by tampering the boolean value of parameters "isAdmin" and "isPremium" located on device storage.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-29022 ‼
📖 Read
via "National Vulnerability Database".
Failure to Sanitize host header value on output in the GateManager Web server could allow an attacker to conduct web cache poisoning attacks. This issue affects Secomea GateManager all versions prior to 9.3📖 Read
via "National Vulnerability Database".
‼ CVE-2020-35558 ‼
📖 Read
via "National Vulnerability Database".
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an SSRF in thein the MySQL access check, allowing an attacker to scan for open ports and gain some information about possible credentials..📖 Read
via "National Vulnerability Database".
🕴 Under Attack: Hosting & Internet Service Providers 🕴
📖 Read
via "Dark Reading".
The digital universe depends on always-on IT networks and services, so ISPs and hosting providers have become favorite targets for cyberattacks.📖 Read
via "Dark Reading".
Dark Reading
Under Attack: Hosting & Internet Service Providers
The digital universe depends on always-on IT networks and services, so ISPs and hosting providers have become favorite targets for cyberattacks.
🦿 The fine line between global COVID-19 protocols and privacy 🦿
📖 Read
via "Tech Republic".
A panel of experts considers the best methods for safe domestic and international air travel including proof of testing, vaccination passports, and digital health passes.📖 Read
via "Tech Republic".
TechRepublic
The fine line between global COVID-19 protocols and privacy
A panel of experts considers the best methods for safe domestic and international air travel including proof of testing, vaccination passports, and digital health passes.
🔏 Sandworm Linked to French Hacking Campaign 🔏
📖 Read
via "Digital Guardian".
France's cybersecurity agency connected a three year intrusion campaign targeting monitoring software to Russia's Sandworm group.📖 Read
via "Digital Guardian".
Digital Guardian
Sandworm Linked to French Hacking Campaign
France's cybersecurity agency connected a three year intrusion campaign targeting monitoring software to Russia's Sandworm group.