Tag
#sql
Human Resource Management System 2024 version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
Hotel Management System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
Home Owners Collection Management System version 1.0 suffers from an ignored default credential vulnerability.
Bhojon Restaurant Management System version 3.0 suffers from an insecure direct object reference vulnerability.
Stash up to v0.25.1 was discovered to contain a SQL injection vulnerability via the sort parameter.
Feberr version 13.4 suffers from an ignored default credential vulnerability.
Farmacia Gama version 1.0 suffers from a cross site scripting vulnerability.
Covid-19 Contact Tracing System version 1.0 suffers from a cross site scripting vulnerability.
Bhojon Restaurant Management System version 2.9 suffers from an ignored default credential vulnerability.
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global). View CSAF 1. EXECUTIVE SUMMARY CVSS v4 9.4 ATTENTION: Exploitable remotely/low attack complexity Vendor: Siemens Equipment: SINEC NMS Vulnerabilities: Use After Free, Improper Input Validation, Deserialization of Untrusted Data, Improper Restriction of Operations within the Bounds of a Memory Buffer, Uncontrolled Resource Consumption, Out-of-bounds Read, Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion'), Privilege Dropping / Lowering Errors, Allocation of Resources Without Limits or Throttling, Execution with Unnecessary Privileges, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Incorrect Authorization 2. RIS...