3 results (0.003 seconds)

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 1

16 Nov 2018 — SaltOS 3.1 r8126 allows action=login&querystring=&user=[SQL] SQL Injection. SaltOS 3.1 r8126 permite la inyección SQL en action=loginquerystring=user=[SQL]. • https://www.exploit-db.com/exploits/45731 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 3

29 Oct 2018 — SaltOS 3.1 r8126 allows action=ajax&query=numbers&page=usuarios&action2=[SQL] SQL Injection. SaltOS 3.1 r8126 permite la inyección SQL en action=ajaxquery=numberspage=usuariosaction2=[SQL]. SaltOS Erp Crm version 3.1 r8126 suffers from multiple remote SQL injection vulnerabilities. • https://packetstorm.news/files/id/150004 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 6.5EPSS: 0%CPEs: 1EXPL: 3

29 Oct 2018 — SaltOS 3.1 r8126 contains a database download vulnerability. SaltOS 3.1 r8126 contiene una vulnerabilidad de descarga de base de datos. Erp Crm version 3.1 r8126 suffers from a database download vulnerability. • https://packetstorm.news/files/id/150005 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •