Autore: Angelo Barbosa

CVE-2023-6579 | osCommerce 4 POST Parameter shopping-cart estimate[country_id] sql injection

A vulnerability, which was classified as critical, has been found in osCommerce 4. Affected by this issue is some unknown functionality of the file /b2b-supermarket/shopping-cart of the component POST Parameter Handler. The manipulation of the argument estimate[country_id] leads to sql injection. This vulnerability is handled as CVE-2023-6579. The attack may be launched remotely. Furthermore, there is an exploit available. The vendor was contacted early about this disclosure but did not respond in any...

Per saperne di più

CVE-2023-49956 | Dalmann OCPP.Core up to 1.2.x StopTransaction Message random values

A vulnerability classified as problematic was found in Dalmann OCPP.Core up to 1.2.x. Affected by this vulnerability is an unknown functionality of the component StopTransaction Message Handler. The manipulation leads to insufficiently random values. This vulnerability is known as CVE-2023-49956. The attack needs to be done within the local network. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2023-6578 | Software AG WebMethods 10.11.x/10.15.x wm.server/connect/ access control

A vulnerability classified as critical has been found in Software AG WebMethods 10.11.x/10.15.x. Affected is an unknown function of the file wm.server/connect/. The manipulation leads to improper access controls. This vulnerability is traded as CVE-2023-6578. It is possible to launch the attack remotely. There is no exploit available. The vendor was contacted early about this disclosure but did not respond in any...

Per saperne di più

CVE-2023-6577 | Beijing Baichuo PatrolFlow 2530Pro up to 20231126 /log/mailsendview.php file path traversal

A vulnerability was found in Beijing Baichuo PatrolFlow 2530Pro up to 20231126. It has been rated as problematic. This issue affects some unknown processing of the file /log/mailsendview.php. The manipulation of the argument file with the input /boot/phpConfig/tb_admin.txt leads to path traversal. The identification of this vulnerability is CVE-2023-6577. The attack may be initiated remotely. Furthermore, there is an exploit available. The vendor was contacted early about this disclosure but did not respond in any...

Per saperne di più

CVE-2023-6576 | Beijing Baichuo S210 up to 20231123 HTTP POST Request /Tool/uploadfile.php file_upload unrestricted upload

A vulnerability was found in Beijing Baichuo S210 up to 20231123. It has been declared as critical. This vulnerability affects unknown code of the file /Tool/uploadfile.php of the component HTTP POST Request Handler. The manipulation of the argument file_upload leads to unrestricted upload. This vulnerability was named CVE-2023-6576. The attack can be initiated remotely. Furthermore, there is an exploit available. The vendor was contacted early about this disclosure but did not respond in any...

Per saperne di più