Skip to main content

Vendor/product archive

blaauwproducts / remote_kiln_control CVEs

Beta · best-effort

9 CVEs tagged to blaauwproducts / remote_kiln_control2 Critical, 5 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2019-18871

Published May 7, 2020

A path traversal in debug.php accessed via default.php in Blaauw Remote Kiln Control through v3.00r4 allows an authenticated attacker to upload arbitrary files, leading to arbitra…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-18870

Published May 7, 2020

A path traversal via the iniFile parameter in excel.php in Blaauw Remote Kiln Control through v3.00r4 allows an authenticated attacker to download arbitrary files from the host ma…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-18869

Published May 7, 2020

Leftover Debug Code in Blaauw Remote Kiln Control through v3.00r4 allows a user to execute arbitrary php code via /default.php?idx=17.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-18866

Published May 7, 2020

Unauthenticated SQL injection via the username in the login mechanism in Blaauw Remote Kiln Control through v3.00r4 allows a user to extract arbitrary data from the rkc database.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-18864

Published May 7, 2020

/server-info and /server-status in Blaauw Remote Kiln Control through v3.00r4 allow an unauthenticated attacker to gain sensitive information about the host machine.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-18867

Published May 7, 2020

Browsable directories in Blaauw Remote Kiln Control through v3.00r4 allow an attacker to enumerate sensitive filenames and locations, including source code. This affects /ajax/, /…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-18865

Published May 7, 2020

Information disclosure via error message discrepancies in authentication functions in Blaauw Remote Kiln Control through v3.00r4 allows an unauthenticated attacker to enumerate va…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1