Computrols
computrols
10 CVEs • 2 products
Products (2)
Click to collapseToggle
Products (2)
Click to collapse
CVEs (10)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Computrols 1Computrols Building Automation Software Jun 17, 2026 May 24, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Computrols CBAS 18.0.0 allows Username Enumeration. |
1Computrols 1Computrols Building Automation Software Jun 17, 2026 May 24, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Computrols CBAS 18.0.0 allows Cross-Site Request Forgery. |
1Computrols 1Computrols Building Automation Software Jun 17, 2026 May 23, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Computrols CBAS 18.0.0 has Default Credentials. |
1Computrols 1Computrols Building Automation Software Jun 17, 2026 May 23, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Computrols CBAS 18.0.0 allows unprotected Subversion (SVN) directory / source code disclosure. |
1Computrols 1Computrols Building Automation System Jun 17, 2026 May 23, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Computrols CBAS 18.0.0 allows Unauthenticated Reflected Cross-Site Scripting vulnerabilities in the login page and password reset page via the username GET parameter. |
1Computrols 1Computrols Building Automation Software Jun 17, 2026 May 23, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Computrols CBAS 18.0.0 mishandles password hashes. The approach is MD5 with a pw prefix, e.g., if the password is admin, it will calculate the MD5 hash of pwadmin and store it in a MySQL database. |
1Computrols 1Computrols Building Automation Software Jun 17, 2026 May 23, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Computrols CBAS 18.0.0 allows Authenticated Command Injection. |
1Computrols 1Computrols Building Automation Software Jun 17, 2026 May 23, 2019 N/A· v4 8.1 HIGH· v3 8.3 HIGH· v2 Computrols CBAS 18.0.0 allows Authentication Bypass. |
1Computrols 1Computrols Building Automation Software Jun 17, 2026 May 23, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Computrols CBAS 18.0.0 allows Authenticated Blind SQL Injection via the id GET parameter, as demonstrated by the index.php?m=servers&a=start_pulling&id= substring. |
1Computrols 1Computrols Building Automation Software Jun 17, 2026 May 23, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Computrols CBAS 18.0.0 has hard-coded encryption keys. |