Show filters
81 Total Results
Displaying 41-50 of 81
Sort by:
Attacker Value
Unknown

CVE-2022-48587

Disclosure Date: August 09, 2023 (last updated November 08, 2023)
A SQL injection vulnerability exists in the “schedule editor” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.
Attacker Value
Unknown

CVE-2022-48586

Disclosure Date: August 09, 2023 (last updated November 08, 2023)
A SQL injection vulnerability exists in the “json walker” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.
Attacker Value
Unknown

CVE-2022-48585

Disclosure Date: August 09, 2023 (last updated November 08, 2023)
A SQL injection vulnerability exists in the “admin brand portal” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.
Attacker Value
Unknown

CVE-2022-48584

Disclosure Date: August 09, 2023 (last updated November 08, 2023)
A command injection vulnerability exists in the download and convert report feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a shell command. This allows for the injection of arbitrary commands to the underlying operating system.
Attacker Value
Unknown

CVE-2022-48583

Disclosure Date: August 09, 2023 (last updated November 08, 2023)
A command injection vulnerability exists in the dashboard scheduler feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a shell command. This allows for the injection of arbitrary commands to the underlying operating system.
Attacker Value
Unknown

CVE-2022-48582

Disclosure Date: August 09, 2023 (last updated October 08, 2023)
A command injection vulnerability exists in the ticket report generate feature of the ScienceLogic SL1 that takes unsanitized user controlled input and passes it directly to a shell command. This allows for the injection of arbitrary commands to the underlying operating system.
Attacker Value
Unknown

CVE-2022-48581

Disclosure Date: August 09, 2023 (last updated October 08, 2023)
A command injection vulnerability exists in the “dash export” feature of the ScienceLogic SL1 that takes unsanitized user controlled input and passes it directly to a shell command. This allows for the injection of arbitrary commands to the underlying operating system.
Attacker Value
Unknown

CVE-2022-48580

Disclosure Date: August 09, 2023 (last updated October 08, 2023)
A command injection vulnerability exists in the ARP ping device tool feature of the ScienceLogic SL1 that takes unsanitized user controlled input and passes it directly to a shell command. This allows for the injection of arbitrary commands to the underlying operating system.
Attacker Value
Unknown

CVE-2023-27618

Disclosure Date: June 22, 2023 (last updated October 08, 2023)
Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in AGILELOGIX Store Locator WordPress plugin <= 1.4.9 versions.
Attacker Value
Unknown

CVE-2015-20108

Disclosure Date: May 27, 2023 (last updated October 08, 2023)
xml_security.rb in the ruby-saml gem before 1.0.0 for Ruby allows XPath injection and code execution because prepared statements are not used.