ZeroHour

Vulnerabilities

4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2016-6545
+1 in the same advisory: …6542
Session cookies are not used for maintaining valid sessions in iTrack Easy.

Session cookies are not used for maintaining valid sessions in iTrack Easy. The user's password is passed as a POST parameter over HTTPS using a base64 encoded passwd field on every request. In this implementation, sessions can only be terminated when the user changes the associated password.

NVD description · AI analysis pending
9.8
group max
3%
  • ieasytec itrackeasy
CVE-2016-6544
+1 in the same advisory: …6543
getgps data in iTrack Easy can be modified without authentication by setting the data using the parametercmd:setothergps.

getgps data in iTrack Easy can be modified without authentication by setting the data using the parametercmd:setothergps. This vulnerability can be exploited to alter the GPS data of a lost device.

NVD description · AI analysis pending
7.5
group max
3%
  • ieasytec itrack easy