Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown
CVE-2024-3707
Disclosure Date: April 12, 2024 (last updated July 05, 2024)
Information exposure vulnerability in OpenGnsys affecting version 1.1.1d (Espeto). This vulnerability allows an attacker to enumerate all files in the web tree by accessing a php file.
0
Attacker Value
Unknown
CVE-2024-3706
Disclosure Date: April 12, 2024 (last updated July 05, 2024)
Information exposure vulnerability in OpenGnsys affecting version 1.1.1d (Espeto). This vulnerability allows an attacker to view a php backup file (controlaccess.php-LAST) where database credentials are stored.
0
Attacker Value
Unknown
CVE-2024-3705
Disclosure Date: April 12, 2024 (last updated April 13, 2024)
Unrestricted file upload vulnerability in OpenGnsys affecting version 1.1.1d (Espeto). This vulnerability allows an attacker to send a POST request to the endpoint '/opengnsys/images/M_Icons.php' modifying the file extension, due to lack of file extension verification, resulting in a webshell injection.
0
Attacker Value
Unknown
CVE-2024-3704
Disclosure Date: April 12, 2024 (last updated April 13, 2024)
SQL Injection Vulnerability has been found on OpenGnsys product affecting version 1.1.1d (Espeto). This vulnerability allows an attacker to inject malicious SQL code into login page to bypass it or even retrieve all the information stored in the database.
0