Vulnerabilities
Vulnerable Software
Computrols CBAS 18.0.0 allows Cross-Site Request Forgery.
CVSS Score
8.8
EPSS Score
0.005
Published
2019-05-24
Computrols CBAS 18.0.0 allows Username Enumeration.
CVSS Score
5.3
EPSS Score
0.052
Published
2019-05-24
Computrols CBAS 18.0.0 allows unprotected Subversion (SVN) directory / source code disclosure.
CVSS Score
7.5
EPSS Score
0.121
Published
2019-05-23
Computrols CBAS 18.0.0 has Default Credentials.
CVSS Score
9.8
EPSS Score
0.004
Published
2019-05-23
Computrols CBAS 18.0.0 mishandles password hashes. The approach is MD5 with a pw prefix, e.g., if the password is admin, it will calculate the MD5 hash of pwadmin and store it in a MySQL database.
CVSS Score
7.5
EPSS Score
0.001
Published
2019-05-23
Computrols CBAS 18.0.0 has hard-coded encryption keys.
CVSS Score
6.5
EPSS Score
0.001
Published
2019-05-23
Computrols CBAS 18.0.0 allows Authenticated Blind SQL Injection via the id GET parameter, as demonstrated by the index.php?m=servers&a=start_pulling&id= substring.
CVSS Score
8.8
EPSS Score
0.005
Published
2019-05-23
Computrols CBAS 18.0.0 allows Authentication Bypass.
CVSS Score
8.1
EPSS Score
0.004
Published
2019-05-23
Computrols CBAS 18.0.0 allows Authenticated Command Injection.
CVSS Score
8.8
EPSS Score
0.136
Published
2019-05-23


Contact Us

Shodan ® - All rights reserved