5
CVSSv2

CVE-2015-7902

Published: 28/10/2015 Updated: 28/10/2015
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Infinite Automation Mango Automation 2.5.x and 2.6.x prior to 2.6.0 build 430 provides different error messages for failed login attempts in unspecified circumstances, which allows remote malicious users to obtain sensitive information via a series of requests.

Vulnerable Product Search on Vulmon Subscribe to Product

infinite automation systems mango automation 2.5.0

infinite automation systems mango automation 2.5.5

infinite automation systems mango automation 2.6.0

Exploits

Mango Automation 260 CSRF File Upload And Arbitrary JSP Code Execution Vendor: Infinite Automation Systems Inc Product web page: wwwinfiniteautomationcom/ Affected version: 252 and 260 beta (build 327) Summary: Mango Automation is a flexible SCADA, HMI And Automation software application that allows you to view, log, graph, anima ...