CVE-2024-31705 – GLPI 10.x.x Remote Command Execution
https://notcve.org/view.php?id=CVE-2024-31705
An issue in Infotel Conseil GLPI v.10.X.X and after allows a remote attacker to execute arbitrary code via the insufficient validation of user-supplied input. ... GLPI versions 10.x.x suffers from a remote command execution vulnerability via the shell commands plugin. • https://github.com/V3locidad/GLPI_POC_Plugins_Shell https://seclists.org/fulldisclosure/2024/Apr/23 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •
CVE-2024-3788 – Improper Neutralization of Server-Side Includes (SSI) vulnerability in WBSAirback
https://notcve.org/view.php?id=CVE-2024-3788
Exploitation of this vulnerability could allow a remote user to execute arbitrary code. • https://github.com/7Ragnarok7/CVE-2024-37888 https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-wbsairback-white-bear-solutions •
CVE-2024-3787 – Improper Neutralization of Server-Side Includes (SSI) vulnerability in WBSAirback
https://notcve.org/view.php?id=CVE-2024-3787
Exploitation of this vulnerability could allow a remote user to execute arbitrary code. • https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-wbsairback-white-bear-solutions •
CVE-2024-3786 – Improper Neutralization of Server-Side Includes (SSI) vulnerability in WBSAirback
https://notcve.org/view.php?id=CVE-2024-3786
Exploitation of this vulnerability could allow a remote user to execute arbitrary code. • https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-wbsairback-white-bear-solutions • CWE-94: Improper Control of Generation of Code ('Code Injection') •
CVE-2024-3785 – Improper Neutralization of Server-Side Includes (SSI) vulnerability in WBSAirback
https://notcve.org/view.php?id=CVE-2024-3785
Exploitation of this vulnerability could allow a remote user to execute arbitrary code. • https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-wbsairback-white-bear-solutions • CWE-94: Improper Control of Generation of Code ('Code Injection') •