VYPR

CWE-668

Exposure of Resource to Wrong Sphere

ClassDraft

Description

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

Hierarchy (View 1000)

CVEs mapped to this weakness (796)

page 12 of 40
  • CVE-2020-21503HigOct 5, 2021
    risk 0.49cvss 7.5epss 0.01

    waimai Super Cms 20150505 has a logic flaw allowing attackers to modify a price, before form submission, by observing data in a packet capture. By setting the index.php?m=gift&a=addsave credit parameter to -1, the product is sold for free.

  • CVE-2021-36749MedSep 24, 2021
    risk 0.49cvss 6.5epss 0.81

    In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticated users to read data from other sources than intended, such as the local file system, with the privileges of the Druid server…

  • CVE-2021-22009HigSep 23, 2021
    risk 0.49cvss 7.5epss 0.01

    The vCenter Server contains multiple denial-of-service vulnerabilities in VAPI (vCenter API) service. A malicious actor with network access to port 443 on vCenter Server may exploit these issues to create a denial of service condition due to excessive memory consumption by VAPI…

  • CVE-2021-40639HigSep 15, 2021
    risk 0.49cvss 7.5epss 0.01

    Improper access control in Jfinal CMS 5.1.0 allows attackers to access sensitive information via /classes/conf/db.properties&config=filemanager.config.js.

  • CVE-2021-23034HigSep 14, 2021
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP version 16.x before 16.1.0 and 15.1.x before 15.1.3.1, when a DNS profile using a DNS cache resolver is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) process to terminate. Note: Software versions which have…

  • CVE-2021-21996HigSep 8, 2021
    risk 0.49cvss 7.5epss 0.04

    An issue was discovered in SaltStack Salt before 3003.3. A user who has control of the source, and source_hash URLs can gain full file system access as root on a salt minion.

  • CVE-2021-38712HigAug 16, 2021
    risk 0.49cvss 7.5epss 0.01

    OneNav 0.9.12 allows Information Disclosure of the onenav.db3 contents. NOTE: the vendor's recommended solution is to block the access via an NGINX configuration file.

  • CVE-2021-36793HigAug 13, 2021
    risk 0.49cvss 7.5epss 0.01

    The routes (aka Extbase Yaml Routes) extension before 2.1.1 for TYPO3, when CsrfTokenViewHelper is used, allows Sensitive Information Disclosure because a session identifier is unsafely present in HTML output.

  • CVE-2020-18754HigAug 13, 2021
    risk 0.49cvss 7.5epss 0.01

    An information disclosure vulnerability exists within Dut Computer Control Engineering Co.'s PLC MAC1100.

  • CVE-2020-27361HigJul 1, 2021
    risk 0.49cvss 7.5epss 0.07

    An issue exists within Akkadian Provisioning Manager 4.50.02 which allows attackers to view sensitive information within the /pme subdirectories.

  • CVE-2020-18647HigJun 22, 2021
    risk 0.49cvss 7.5epss 0.02

    Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/nonecms/vendor".

  • CVE-2020-18646HigJun 22, 2021
    risk 0.49cvss 7.5epss 0.02

    Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/public/index.php".

  • CVE-2020-10581HigMar 25, 2021
    risk 0.49cvss 7.5epss 0.01

    Multiple session validity check issues in several administration functionalities of Invigo Automatic Device Management (ADM) through 5.0 allow remote attackers to read potentially sensitive data hosted by the application.

  • CVE-2015-9550HigNov 24, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered on TOTOLINK A850R-V1 through 1.0.1-B20150707.1612 and F1-V2 through 1.1-B20150708.1646 devices. By sending a specific hel,xasf packet to the WAN interface, it is possible to open the web management interface on the WAN interface.

  • CVE-2020-26868HigOct 12, 2020
    risk 0.49cvss 7.5epss 0.02

    ARC Informatique PcVue prior to version 12.0.17 is vulnerable to a denial-of-service attack due to the ability of an unauthorized user to modify information used to validate messages sent by legitimate web clients. This issue also affects third-party systems based on the Web…

  • CVE-2020-26602HigOct 6, 2020
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in EthernetNetwork on Samsung mobile devices with O(8.1), P(9.0), Q(10.0), and R(11.0) software. PendingIntent allows sdcard access by an unprivileged process. The Samsung ID is SVE-2020-18392 (October 2020).

  • CVE-2020-13343HigOct 6, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue has been discovered in GitLab affecting all versions starting from 11.2. Unauthorized Users Can View Custom Project Template

  • CVE-2020-5386HigSep 2, 2020
    risk 0.49cvss 7.5epss 0.01

    Dell EMC ECS, versions prior to 3.5, contains an Exposure of Resource vulnerability. A remote unauthenticated attacker can access the list of DT (Directory Table) objects of all internally running services and gain knowledge of sensitive data of the system.

  • CVE-2020-10238HigMar 16, 2020
    risk 0.49cvss 7.5epss 0.05

    An issue was discovered in Joomla! before 3.9.16. Various actions in com_templates lack the required ACL checks, leading to various potential attack vectors.

  • CVE-2019-10805HigFeb 28, 2020
    risk 0.49cvss 7.5epss 0.01

    valib through 2.0.0 allows Internal Property Tampering. A maliciously crafted JavaScript object can bypass several inspection functions provided by valib. Valib uses a built-in function (hasOwnProperty) from the unsafe user-input to examine an object. It is possible for a…