CVE-2020-4921
https://notcve.org/view.php?id=CVE-2020-4921
20 Jan 2021 — IBM Security Guardium 10.6 and 11.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 191398. IBM Security Guardium versiones 10.6 y 11.2, es vulnerable a una inyección SQL. Un atacante remoto podría enviar sentencias SQL especialmente diseñadas, lo que podría permitir al atacante visualizar, agregar, modificar o eliminar información en la base... • https://exchange.xforce.ibmcloud.com/vulnerabilities/191398 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2020-4688
https://notcve.org/view.php?id=CVE-2020-4688
20 Jan 2021 — IBM Security Guardium 10.6 and 11.2 could allow a local attacker to execute arbitrary commands on the system as an unprivileged user, caused by command injection vulnerability. IBM X-Force ID: 186700. IBM Security Guardium versiones 10.6 y 11.2, podrían permitir a un atacante local ejecutar comandos arbitrarios en el sistema como un usuario sin privilegios, causado por una vulnerabilidad de inyección de comandos. IBM X-Force ID: 186700 • https://exchange.xforce.ibmcloud.com/vulnerabilities/186700 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •
CVE-2020-4689
https://notcve.org/view.php?id=CVE-2020-4689
12 Oct 2020 — IBM Security Guardium 11.2 is vulnerable to CVS Injection. A remote privileged attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-ForceID: 186696. IBM Security Guardium versión 11.2, es vulnerable a una Inyección CVS. Un atacante privilegiado remoto podría ejecutar comandos arbitrarios en el sistema, causados por una comprobación inapropiada del contenido del archivo csv. • https://exchange.xforce.ibmcloud.com/vulnerabilities/186696 • CWE-1236: Improper Neutralization of Formula Elements in a CSV File •
CVE-2020-4681
https://notcve.org/view.php?id=CVE-2020-4681
12 Oct 2020 — IBM Security Guardium 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186427. IBM Security Guardium versión 11.2, es vulnerable a un ataque de tipo cross-site scripting almacenado. Esta vulnerabilidad permite a usuarios insertar código JavaScript arbitrario en la Interfaz de Usuario Web, alterando as... • https://exchange.xforce.ibmcloud.com/vulnerabilities/186427 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2020-4680
https://notcve.org/view.php?id=CVE-2020-4680
12 Oct 2020 — IBM Security Guardium 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186426. IBM Security Guardium versión 11.2, es vulnerable a un ataque de tipo cross-site scripting almacenado. Esta vulnerabilidad permite a usuarios insertar código JavaScript arbitrario en la Interfaz de Usuario Web, alterando as... • https://exchange.xforce.ibmcloud.com/vulnerabilities/186426 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2020-4679
https://notcve.org/view.php?id=CVE-2020-4679
12 Oct 2020 — IBM Security Guardium 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186424. IBM Security Guardium versión 11.2, es vulnerable a un ataque de tipo cross-site scripting almacenado. Esta vulnerabilidad permite a usuarios insertar código JavaScript arbitrario en la Interfaz de Usuario Web, alterando as... • https://exchange.xforce.ibmcloud.com/vulnerabilities/186424 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2020-4678
https://notcve.org/view.php?id=CVE-2020-4678
12 Oct 2020 — IBM Security Guardium 11.2 could allow an attacker with admin access to obtain and read files that they normally would not have access to. IBM X-Force ID: 186423. IBM Security Guardium versión 11.2, podría permitir a un atacante con acceso de administrador conseguir y leer archivos a los que normalmente no tendría acceso. IBM X-Force ID: 186423 • https://exchange.xforce.ibmcloud.com/vulnerabilities/186423 •
CVE-2014-7169 – GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2014-7169
25 Sep 2014 — GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a ... • https://www.exploit-db.com/exploits/34777 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CWE-228: Improper Handling of Syntactically Invalid Structure •
CVE-2014-6271 – GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2014-6271
24 Sep 2014 — GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." ... • https://github.com/darrenmartyn/visualdoor • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CWE-94: Improper Control of Generation of Code ('Code Injection') •