Show filters
2 Total Results
Displaying 1-2 of 2
Sort by:
Attacker Value
Unknown

CVE-2024-7729

Disclosure Date: August 14, 2024 (last updated February 26, 2025)
The CAYIN Technology CMS lacks proper access control, allowing unauthenticated remote attackers to download arbitrary CGI files.
0
Attacker Value
Unknown

CVE-2024-7728

Disclosure Date: August 14, 2024 (last updated February 26, 2025)
The specific CGI of the CAYIN Technology CMS does not properly validate user input, allowing a remote attacker with administrator privileges to inject OS commands into the specific parameter and execute them on the remote server.
0