Dreamreport

Dream Report

5 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.05%
  • Veröffentlicht 09.04.2021 18:15:12
  • Zuletzt bearbeitet 21.11.2024 05:01:26

A privilege escalation vulnerability exists in Dream Report 5 R20-2. In the default configuration, the Syncfusion Dashboard Service service binary can be replaced by attackers to escalate privileges to NT SYSTEM. An attacker can provide a malicious f...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 09.04.2021 18:15:12
  • Zuletzt bearbeitet 21.11.2024 05:01:26

A privilege escalation vulnerability exists in Dream Report 5 R20-2. IIn the default configuration, the following registry keys, which reference binaries with weak permissions, can be abused by attackers to effectively ‘backdoor’ the installation fil...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 09.04.2021 18:15:12
  • Zuletzt bearbeitet 21.11.2024 05:01:26

A privilege escalation vulnerability exists in Dream Report 5 R20-2. COM Class Identifiers (CLSID), installed by Dream Report 5 20-2, reference LocalServer32 and InprocServer32 with weak privileges which can lead to privilege escalation when used. An...

  • EPSS 2.03%
  • Veröffentlicht 10.02.2012 19:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Cross-site scripting (XSS) vulnerability in Invensys Wonderware HMI Reports 3.42.835.0304 and earlier, as used in Ocean Data Systems Dream Report before 4.0 and other products, allows remote attackers to inject arbitrary web script or HTML via unspec...

  • EPSS 3.32%
  • Veröffentlicht 10.02.2012 19:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Invensys Wonderware HMI Reports 3.42.835.0304 and earlier, as used in Ocean Data Systems Dream Report before 4.0 and other products, allows user-assisted remote attackers to execute arbitrary code via a malformed file that triggers a "write access vi...