VendorsInvigoautomatic_device_managementall versions
Vulnerabilities

Invigo Automatic Device Management

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2020-10582
A SQL injection on the /admin/display_errors.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote attackers to execute arbitrary SQL requests (including data reading and modification) on the database.
Published 2021-03-25 · Modified
9.8EPSS 0.016
CVE-2020-10583
The /admin/admapi.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote authenticated attackers to execute arbitrary OS commands on the server as the user running the application.
Published 2021-03-25 · Modified
9.0EPSS 0.028
CVE-2020-10580
A command injection on the /admin/broadcast.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote authenticated attackers to execute arbitrary PHP code on the server as the user running the application.
Published 2021-03-25 · Modified
8.8EPSS 0.039
CVE-2020-10579
A directory traversal on the /admin/sysmon.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote attackers to list the content of arbitrary server directories accessible to the user running the application.
Published 2021-03-25 · Modified
7.5EPSS 0.022
CVE-2020-10584
A directory traversal on the /admin/search_by.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote attackers to read arbitrary server files accessible to the user running the application.
Published 2021-03-25 · Modified
7.5EPSS 0.022
CVE-2020-10581
Multiple session validity check issues in several administration functionalities of Invigo Automatic Device Management (ADM) through 5.0 allow remote attackers to read potentially sensitive data hosted by the application.
Published 2021-03-25 · Modified
7.5EPSS 0.013