Skip to content
Noroxi

computrols records

10 published records for vendor computrols.

All records

10 records
  • Computrols CBAS 18.0.0 has Default Credentials.

    CriticalCVSS 9.8No exploitEPSS 2%

    computrols · computrols building automation softwareMay 23, 2019

  • Computrols CBAS 18.0.0 allows Authenticated Command Injection.

    HighCVSS 8.8No exploitEPSS 3%

    computrols · computrols building automation softwareMay 23, 2019

  • Computrols CBAS 18.0.0 allows Cross-Site Request Forgery.

    HighCVSS 8.8Proof of conceptEPSS 2%

    computrols · computrols building automation softwareMay 24, 2019

  • Computrols CBAS 18.0.0 allows Authenticated Blind SQL Injection via the id GET parameter, as demonstrated by the index.php?m=servers&a=start

    HighCVSS 8.8No exploitEPSS 2%

    computrols · computrols building automation softwareMay 23, 2019

  • Computrols CBAS 18.0.0 allows unprotected Subversion (SVN) directory / source code disclosure.

    HighCVSS 7.5Proof of conceptEPSS 9%

    computrols · computrols building automation softwareMay 23, 2019

  • Computrols CBAS 18.0.0 allows Authentication Bypass.

    HighCVSS 8.1No exploitEPSS 2%

    computrols · computrols building automation softwareMay 23, 2019

  • Computrols CBAS 18.0.0 mishandles password hashes.

    HighCVSS 7.5No exploitEPSS 1%

    computrols · computrols building automation softwareMay 23, 2019

  • Computrols CBAS 18.0.0 has hard-coded encryption keys.

    MediumCVSS 6.5No exploitEPSS 1%

    computrols · computrols building automation softwareMay 23, 2019

  • Computrols CBAS 18.0.0 allows Unauthenticated Reflected Cross-Site Scripting vulnerabilities in the login page and password reset page via t

    MediumCVSS 6.1Proof of conceptEPSS 5%

    computrols · computrols building automation systemMay 23, 2019

  • Computrols CBAS 18.0.0 allows Username Enumeration.

    MediumCVSS 5.3Proof of conceptEPSS 8%

    computrols · computrols building automation softwareMay 24, 2019