Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In January 2020
The WP Database Backup plugin through 5.5 for WordPress stores downloads by default locally in the directory wp-content/uploads/db-backup/. This might allow attackers to read ZIP archives by guessing random ID numbers, guessing date strings with a 2020_{0..1}{0..2}_{0..3}{0..9} format, guessing UNIX timestamps, and making HTTPS requests with the complete guessed URL.
CVSS Score
7.5
EPSS Score
0.005
Published
2020-01-20
TestLink before 1.9.20 allows XSS via non-lowercase javascript: in the index.php reqURI parameter. NOTE: this issue exists because of an incomplete fix for CVE-2019-19491.
CVSS Score
6.1
EPSS Score
0.004
Published
2020-01-20
An issue was discovered in Gallagher Command Centre 7.x before 7.90.991(MR5), 8.00 before 8.00.1161(MR5), and 8.10 before 8.10.1134(MR4). External system configuration data (used for third party integrations such as DVR systems) were logged in the Command Centre event trail. Any authenticated operator with the 'view events' privilege could see the full configuration, including cleartext usernames and passwords, under the event details of a Modified DVR System event.
CVSS Score
5.5
EPSS Score
0.001
Published
2020-01-20
Cacti 1.2.8 allows Remote Code Execution (by privileged users) via shell metacharacters in the Performance Boost Debug Log field of poller_automation.php. OS commands are executed when a new poller cycle begins. The attacker must be authenticated, and must have access to modify the Performance Settings of the product.
CVSS Score
8.8
EPSS Score
0.468
Published
2020-01-20
UHP UHP-100 3.4.1.15, 3.4.2.4, and 3.4.3 devices allow XSS via cB3?ta= (profile title).
CVSS Score
6.1
EPSS Score
0.003
Published
2020-01-19
UHP UHP-100 3.4.1.15, 3.4.2.4, and 3.4.3 devices allow XSS via cw2?td= (Site Name field of the Site Setup section).
CVSS Score
6.1
EPSS Score
0.003
Published
2020-01-19
Ruckus ZoneFlex R310 104.0.0.0.1347 devices allow Stored XSS via the SSID field on the Configuration > Radio 2.4G > Wireless X screen (after a successful login to the super account).
CVSS Score
4.8
EPSS Score
0.003
Published
2020-01-19
KMS Controls BAC-A1616BC BACnet devices have a cleartext password of snowman in the BACKDOOR_NAME variable in the BC_Logon.swf file.
CVSS Score
9.8
EPSS Score
0.004
Published
2020-01-19
Evoko Home 1.31 devices provide different error messages for failed login requests depending on whether the username is valid.
CVSS Score
5.3
EPSS Score
0.004
Published
2020-01-19
Evoko Home devices 1.31 through 1.37 allow remote attackers to obtain sensitive information (such as usernames and password hashes) via a WebSocket request, as demonstrated by the sockjs/224/uf1psgff/websocket URI at a wss:// URL.
CVSS Score
7.5
EPSS Score
0.005
Published
2020-01-19


Contact Us

Shodan ® - All rights reserved