Urve

Urve

3 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.52%
  • Veröffentlicht 23.12.2020 16:15:12
  • Zuletzt bearbeitet 21.11.2024 05:24:10

An issue was discovered in URVE Build 24.03.2020. The password of an integration user account (used for the connection of the MS Office 365 Integration Service) is stored in cleartext in configuration files as well as in the database. The following f...

Exploit
  • EPSS 3.41%
  • Veröffentlicht 23.12.2020 16:15:12
  • Zuletzt bearbeitet 21.11.2024 05:24:11

An issue was discovered in URVE Build 24.03.2020. Using the _internal/pc/shutdown.php path, it is possible to shutdown the system. Among others, the following files and scripts are also accessible: _internal/pc/abort.php, _internal/pc/restart.php, _i...

Exploit
  • EPSS 8.78%
  • Veröffentlicht 23.12.2020 16:15:12
  • Zuletzt bearbeitet 21.11.2024 05:24:11

An issue was discovered in URVE Build 24.03.2020. By using the _internal/pc/vpro.php?mac=0&ip=0&operation=0&usr=0&pass=0%3bpowershell+-c+" substring, it is possible to execute a Powershell command and redirect its output to a file under the web root.