VendorsBlaauw Productsremote_kiln_control3.0.0
Vulnerabilities

Blaauw Products Remote Kiln Control 3.0.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2019-18869
Leftover Debug Code in Blaauw Remote Kiln Control through v3.00r4 allows a user to execute arbitrary php code via /default.php?idx=17.
Published 2020-05-07 · Modified
9.8EPSS 0.013
CVE-2019-18868
Blaauw Remote Kiln Control through v3.00r4 allows an unauthenticated attacker to access MySQL credentials in cleartext in /engine/db.inc, /lang/nl.bak, or /lang/en.bak.
Published 2020-05-07 · Modified
9.8EPSS 0.008
CVE-2019-18871
A path traversal in debug.php accessed via default.php in Blaauw Remote Kiln Control through v3.00r4 allows an authenticated attacker to upload arbitrary files, leading to arbitrary remote code execution.
Published 2020-05-07 · Modified
8.8EPSS 0.025
CVE-2019-18864
/server-info and /server-status in Blaauw Remote Kiln Control through v3.00r4 allow an unauthenticated attacker to gain sensitive information about the host machine.
Published 2020-05-07 · Modified
7.5EPSS 0.013
CVE-2019-18867
Browsable directories in Blaauw Remote Kiln Control through v3.00r4 allow an attacker to enumerate sensitive filenames and locations, including source code. This affects /ajax/, /common/, /engine/, /flash/, /images/, /Images/, /jscripts/, /lang/, /layout/, /programs/, and /sms/.
Published 2020-05-07 · Modified
7.5EPSS 0.012
CVE-2019-18866
Unauthenticated SQL injection via the username in the login mechanism in Blaauw Remote Kiln Control through v3.00r4 allows a user to extract arbitrary data from the rkc database.
Published 2020-05-07 · Modified
7.5EPSS 0.012
CVE-2019-18872
Weak password requirements in Blaauw Remote Kiln Control through v3.00r4 allow a user to set short or guessable passwords (e.g., 1 or 1234).
Published 2020-05-07 · Modified
7.5EPSS 0.009
CVE-2019-18870
A path traversal via the iniFile parameter in excel.php in Blaauw Remote Kiln Control through v3.00r4 allows an authenticated attacker to download arbitrary files from the host machine.
Published 2020-05-07 · Modified
6.5EPSS 0.011
CVE-2019-18865
Information disclosure via error message discrepancies in authentication functions in Blaauw Remote Kiln Control through v3.00r4 allows an unauthenticated attacker to enumerate valid usernames.
Published 2020-05-07 · Modified
5.3EPSS 0.011