Trms
trms
5 CVEs • 5 products
Products (5)
Click to collapseToggle
Products (5)
Click to collapse
CVEs (5)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered in the Tightrope Media Carousel digital signage product 7.0.4.104. Due to insecure default permissions on the C:\TRMS\Services directory, an attacker who has gained access to the system can elevat...Show more |
1Trms 1Carousel Digital Signage Nov 21, 2024 Oct 29, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The Tightrope Media Carousel digital signage product 7.0.4.104 contains an arbitrary file upload vulnerability in the Manage Bulletins/Upload feature, which can be leveraged to gain remote code execution. An authenticate...Show more |
The Tightrope Media Carousel Seneca HDn Windows-based appliance 7.0.4.104 is shipped with a default local administrator username and password. This can be found by a limited user account in an "unattend.xml" file left ov...Show more |
1Trms 1Tightrope Media Carousel Nov 21, 2024 Aug 26, 2019 N/A· v4 10.0 CRITICAL· v3 6.4 MEDIUM· v2 The fetch API in Tightrope Media Carousel before 7.1.3 has CarouselAPI/v0/fetch?url= SSRF. This has two potential areas for abuse. First, a specially crafted URL could be used in a phishing attack to hijack the trust the...Show more |
1Trms 1Tightrope Media Carousel Digital Signage Nov 21, 2024 Jul 23, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A Local File Inclusion (LFI) vulnerability exists in the Web Interface API of TightRope Media Carousel Digital Signage before 7.3.5. The RenderingFetch API allows for the downloading of arbitrary files through the use of...Show more |