Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown
CVE-2024-6880
Disclosure Date: January 10, 2025 (last updated January 11, 2025)
During MegaBIP installation process, a user is encouraged to change a default path to administrative portal, as keeping it secret is listed by the author as one of the protection mechanisms.
Publicly available source code of "/registered.php" discloses that path, allowing an attacker to attempt further attacks.
This issue affects MegaBIP software versions below 5.15
0
Attacker Value
Unknown
CVE-2024-6662
Disclosure Date: January 10, 2025 (last updated January 11, 2025)
Websites managed by MegaBIP in versions below 5.15 are vulnerable to Cross-Site Request Forgery (CSRF) as the form available under "/edytor/index.php?id=7,7,0" lacks protection mechanisms.
A user could be tricked into visiting a malicious website, which would send POST request to this endpoint. If the victim is a logged in administrator, this could lead to creation of new accounts and granting of administrative permissions.
0
Attacker Value
Unknown
CVE-2024-6527
Disclosure Date: July 09, 2024 (last updated July 10, 2024)
SQL Injection vulnerability in parameter "w" in file "druk.php" in MegaBIP software allows unauthorized attacker to disclose the contents of the database and obtain administrator's token to modify the content of pages. This issue affects MegaBIP software versions through 5.13.
0
Attacker Value
Unknown
CVE-2024-6160
Disclosure Date: June 24, 2024 (last updated June 24, 2024)
SQL Injection vulnerability in MegaBIP software allows attacker to disclose the contents of the database, obtain session cookies or modify the content of pages. This issue affects MegaBIP software versions through 5.12.1.
0
Attacker Value
Unknown
CVE-2024-1659
Disclosure Date: June 12, 2024 (last updated August 15, 2024)
Arbitrary File Upload vulnerability in MegaBIP software allows attacker to upload any file to the server (including a PHP code file) without an authentication. This issue affects MegaBIP software versions through 5.10.
0
Attacker Value
Unknown
CVE-2024-1577
Disclosure Date: June 12, 2024 (last updated August 15, 2024)
Remote Code Execution vulnerability in MegaBIP software allows to execute arbitrary code on the server without requiring authentication by saving crafted by the attacker PHP code to one of the website files. This issue affects MegaBIP software versions through 5.11.2.
0
Attacker Value
Unknown
CVE-2024-1576
Disclosure Date: June 12, 2024 (last updated August 15, 2024)
SQL Injection vulnerability in MegaBIP software allows attacker to obtain site administrator privileges, including access to the administration panel and the ability to change the administrator password. This issue affects MegaBIP software versions through 5.09.
0
Attacker Value
Unknown
CVE-2023-5378
Disclosure Date: January 29, 2024 (last updated October 10, 2024)
Improper Input Validation vulnerability in MegaBIP and already unsupported SmodBIP software allows for Stored XSS.This issue affects SmodBIP in all versions and MegaBIP in versions up to 4.36.2. MegaBIP 5.08 was tested and is not vulnerable. A precise range of vulnerable versions remains unknown.
0