Auvesy-mdt

Autosave

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.3%
  • Veröffentlicht 01.04.2022 23:15:09
  • Zuletzt bearbeitet 21.11.2024 06:07:57

An attacker could leverage an API to pass along a malicious file that could then manipulate the process creation command line in MDT AutoSave versions prior to v6.02.06 and run a command line argument. This could then be leveraged to run a malicious ...

  • EPSS 0.21%
  • Veröffentlicht 01.04.2022 23:15:09
  • Zuletzt bearbeitet 21.11.2024 06:07:57

An attacker can gain knowledge of a session temporary working folder where the getfile and putfile commands are used in MDT AutoSave versions prior to v6.02.06. An attacker can leverage this knowledge to provide a malicious command to the working dir...

  • EPSS 0.05%
  • Veröffentlicht 01.04.2022 23:15:09
  • Zuletzt bearbeitet 21.11.2024 06:07:58

An attacker could decipher the encryption and gain access to MDT AutoSave versions prior to v6.02.06.

  • EPSS 0.3%
  • Veröffentlicht 01.04.2022 23:15:09
  • Zuletzt bearbeitet 21.11.2024 06:07:59

An attacker could utilize a function in MDT AutoSave versions prior to v6.02.06 that permits changing a designated path to another path and traversing the directory, allowing the replacement of an existing file with a malicious file.

  • EPSS 0.22%
  • Veröffentlicht 01.04.2022 23:15:09
  • Zuletzt bearbeitet 21.11.2024 06:07:59

An attacker could utilize SQL commands to create a new user MDT AutoSave versions prior to v6.02.06 and update the user’s permissions, granting the attacker the ability to login.

  • EPSS 0.17%
  • Veröffentlicht 01.04.2022 23:15:09
  • Zuletzt bearbeitet 21.11.2024 06:08:00

A function in MDT AutoSave versions prior to v6.02.06 is used to retrieve system information for a specific process, and this information collection executes multiple commands and summarizes the information into an XML. This function and subsequent p...

  • EPSS 0.35%
  • Veröffentlicht 01.04.2022 23:15:09
  • Zuletzt bearbeitet 21.11.2024 06:08:00

A getfile function in MDT AutoSave versions prior to v6.02.06 enables a user to supply an optional parameter, resulting in the processing of a request in a special manner. This can result in the execution of an unzip command and place a malicious .ex...