RSS   Vulnerabilities for 'Automatic device management'   RSS

2021-03-25
 
CVE-2020-10584

CWE-22
 

 
A directory traversal on the /admin/search_by.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote attackers to read arbitrary server files accessible to the user running the application.

 
 
CVE-2020-10583

CWE-78
 

 
The /admin/admapi.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote authenticated attackers to execute arbitrary OS commands on the server as the user running the application.

 
 
CVE-2020-10582

CWE-89
 

 
A SQL injection on the /admin/display_errors.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote attackers to execute arbitrary SQL requests (including data reading and modification) on the database.

 
 
CVE-2020-10581

CWE-668
 

 
Multiple session validity check issues in several administration functionalities of Invigo Automatic Device Management (ADM) through 5.0 allow remote attackers to read potentially sensitive data hosted by the application.

 
 
CVE-2020-10580

CWE-77
 

 
A command injection on the /admin/broadcast.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote authenticated attackers to execute arbitrary PHP code on the server as the user running the application.

 
 
CVE-2020-10579

CWE-22
 

 
A directory traversal on the /admin/sysmon.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote attackers to list the content of arbitrary server directories accessible to the user running the application.

 


Copyright 2021, cxsecurity.com

 

Back to Top