Security Vulnerabilities
- CVEs Published In April 2017
Lens Peek-a-View has a password of 2601hx for the backdoor admin account, a password of user for the backdoor user account, and a password of guest for the backdoor guest account.
iBaby M6 allows remote attackers to obtain sensitive information, related to the ibabycloud.com service.
iBaby M3S has a password of admin for the backdoor admin account.
Summer Baby Zoom Wifi Monitor & Internet Viewing System allows remote attackers to bypass authentication, related to the MySnapCam web service.
Summer Baby Zoom Wifi Monitor & Internet Viewing System allows remote attackers to gain privileges via manual entry of a Settings URL.
Spiceworks Desktop before 2015-12-01 has XSS via an SNMP response.
Castle Rock Computing SNMPc before 2015-12-17 has XSS via SNMP.
Castle Rock Computing SNMPc before 2015-12-17 has SQL injection via the sc parameter.
Opsview before 2015-11-06 has XSS via SNMP.
Liebert MultiLink Automated Shutdown v4.2.4 allows local users to gain privileges by replacing the LiebertM executable file.