Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2019-11232

EXCELLENT INFOTEK BiYan v1.57 ~ v2.8 allows an attacker to leak user information (Password) without being authenticated, by sending an EMP_NO element to the kws_login/asp/query_user.asp URI, and then reading the PWD element.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 71.4%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 5.0
Products affected by CVE-2019-11232
  • Eic » Biyan » Version: 1.57
    cpe:2.3:a:eic:biyan:1.57
  • Eic » Biyan » Version: 2.8
    cpe:2.3:a:eic:biyan:2.8


Contact Us

Shodan ® - All rights reserved