Posted by Matthias Deeg via Fulldisclosure on Sep 05
Advisory ID: SYSS-2024-030
Product: C-MOR Video Surveillance
Manufacturer: za-internet GmbH
Affected Version(s): 5.2401, 6.00PL01
Tested Version(s): 5.2401, 6.00PL01
Vulnerability Type: OS Command Injection (CWE-78)
Risk Level: High
Solution Status: Open
Manufacturer Notification: 2024-04-05
Solution Date: –
Public Disclosure: 2024-09-04…
More Stories
Tiki Wiki CMS Groupware <= 28.3 Two Server-Side Template Injection Vulnerabilities
Posted by Egidio Romano on Jul 09 ---------------------------------------------------------------------------------- Tiki Wiki CMS Groupware <= 28.3 Two Server-Side Template Injection Vulnerabilities ----------------------------------------------------------------------------------...
KL-001-2025-011: Schneider Electric EcoStruxure IT Data Center Expert Unauthenticated Server-Side Request Forgery
Posted by KoreLogic Disclosures via Fulldisclosure on Jul 09 KL-001-2025-011: Schneider Electric EcoStruxure IT Data Center Expert Unauthenticated Server-Side Request...
KL-001-2025-010: Schneider Electric EcoStruxure IT Data Center Expert Privilege Escalation
Posted by KoreLogic Disclosures via Fulldisclosure on Jul 09 KL-001-2025-010: Schneider Electric EcoStruxure IT Data Center Expert Privilege Escalation Title:...
KL-001-2025-009: Schneider Electric EcoStruxure IT Data Center Expert Remote Command Execution
Posted by KoreLogic Disclosures via Fulldisclosure on Jul 09 KL-001-2025-009: Schneider Electric EcoStruxure IT Data Center Expert Remote Command Execution...
KL-001-2025-008: Schneider Electric EcoStruxure IT Data Center Expert Root Password Discovery
Posted by KoreLogic Disclosures via Fulldisclosure on Jul 09 KL-001-2025-008: Schneider Electric EcoStruxure IT Data Center Expert Root Password Discovery...
KL-001-2025-007: Schneider Electric EcoStruxure IT Data Center Expert Unauthenticated Remote Code Execution
Posted by KoreLogic Disclosures via Fulldisclosure on Jul 09 KL-001-2025-007: Schneider Electric EcoStruxure IT Data Center Expert Unauthenticated Remote Code...