Show filters
2,366 Total Results
Displaying 61-70 of 2,366
Sort by:
Attacker Value
Unknown
CVE-2023-5695
Disclosure Date: October 22, 2023 (last updated October 28, 2023)
A vulnerability was found in CodeAstro Internet Banking System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file pages_reset_pwd.php. The manipulation of the argument email with the input testing%40example.com'%26%25<ScRiPt%20>alert(9860)</ScRiPt> leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-243133 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2023-5694
Disclosure Date: October 22, 2023 (last updated October 28, 2023)
A vulnerability was found in CodeAstro Internet Banking System 1.0. It has been classified as problematic. Affected is an unknown function of the file pages_system_settings.php. The manipulation of the argument sys_name with the input <ScRiPt >alert(991)</ScRiPt> leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-243132.
0
Attacker Value
Unknown
CVE-2023-5693
Disclosure Date: October 22, 2023 (last updated January 09, 2024)
A vulnerability was found in CodeAstro Internet Banking System 1.0 and classified as critical. This issue affects some unknown processing of the file pages_reset_pwd.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-243131.
0
Attacker Value
Unknown
CVE-2023-4309
Disclosure Date: October 10, 2023 (last updated October 17, 2023)
Election Services Co. (ESC) Internet Election Service is vulnerable to SQL injection in multiple pages and parameters. These vulnerabilities allow an unauthenticated, remote attacker to read or modify data for any elections that share the same backend database. ESC deactivated older and unused elections and enabled web application firewall (WAF) protection for current and future elections on or around 2023-08-12.
0
Attacker Value
Unknown
CVE-2023-39424
Disclosure Date: September 07, 2023 (last updated October 08, 2023)
A vulnerability in RDPngFileUpload.dll, as used in the IRM Next Generation booking system, allows a remote attacker to upload arbitrary content (such as a web shell component) to the SQL database and execute it with SYSTEM privileges. This vulnerability requires authentication to be exploited but can be paired with another vulnerability in the platform (CVE-2023-39420, which grants access to hardcoded credentials) to carry the attack without having assigned credentials.
0
Attacker Value
Unknown
CVE-2023-39423
Disclosure Date: September 07, 2023 (last updated October 08, 2023)
The RDPData.dll file exposes the /irmdata/api/common endpoint that handles session IDs, among other features. By using a UNION SQL operator, an attacker can leak the sessions table, obtain the currently valid sessions and impersonate a currently logged-in user.
0
Attacker Value
Unknown
CVE-2023-39422
Disclosure Date: September 07, 2023 (last updated October 08, 2023)
The /irmdata/api/ endpoints exposed by the IRM Next Generation booking engine authenticates requests using HMAC tokens. These tokens are however exposed in a JavaScript file loaded on the client side, thus rendering this extra safety mechanism useless.
0
Attacker Value
Unknown
CVE-2023-39421
Disclosure Date: September 07, 2023 (last updated October 08, 2023)
The RDPWin.dll component as used in the IRM Next Generation booking engine includes a set of hardcoded API keys for third-party services such as Twilio and Vonage. These keys allow unrestricted interaction with these services.
0
Attacker Value
Unknown
CVE-2023-39420
Disclosure Date: September 07, 2023 (last updated October 08, 2023)
The RDPCore.dll component as used in the IRM Next Generation booking engine, allows a remote user to connect to customers with an "admin" account and a corresponding password computed daily by a routine inside the DLL file. Once reverse-engineered, this routine can help an attacker generate the daily password and connect to application customers. Given that this is an administrative account, anyone logging into a customer deployment has full, unrestricted access to the application.
0
Attacker Value
Unknown
CVE-2023-28801
Disclosure Date: August 31, 2023 (last updated October 08, 2023)
An Improper Verification of Cryptographic Signature in the SAML authentication of the Zscaler Admin UI allows a Privilege Escalation.This issue affects Admin UI: from 6.2 before 6.2r.
0