Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In February 2023
Due to improper input filtering in the sequalize js library, can malicious queries lead to sensitive information disclosure.
CVSS Score
5.3
EPSS Score
0.001
Published
2023-02-16
TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the province parameter at setting/delStaticDhcpRules.
CVSS Score
9.8
EPSS Score
0.021
Published
2023-02-16
In WAGO Unmanaged Switch (852-111/000-001) in firmware version 01 an undocumented configuration interface without authorization allows an remote attacker to read system information and configure a limited set of parameters.
CVSS Score
9.1
EPSS Score
0.002
Published
2023-02-16
Ricoh mp_c4504ex devices with firmware 1.06 mishandle credentials.
CVSS Score
9.1
EPSS Score
0.002
Published
2023-02-16
Qaelum DOSE 18.08 through 21.1 before 21.2 allows Directory Traversal via the loadimages name parameter. It allows a user to specify an arbitrary location on the server's filesystem from which to load an image. (Only images are displayed to the attacker. All other files are loaded but not displayed.) The Content-Type response header reflects the actual content type of the file being requested. This allows an attacker to enumerate files on the local system. Additionally, remote resources can be requested via a UNC path, allowing an attacker to coerce authentication out from the server to the attackers machine.
CVSS Score
4.3
EPSS Score
0.003
Published
2023-02-16
Improper Restriction of Excessive Authentication Attempts in GitHub repository modoboa/modoboa-installer prior to 2.0.4.
CVSS Score
7.8
EPSS Score
0.002
Published
2023-02-16
The NetModule NSRW web administration interface is vulnerable to path traversals, which could lead to arbitrary file uploads and deletion. By uploading malicious files to the web root directory, authenticated users could gain remote command execution with elevated privileges. This issue affects NSRW: from 4.3.0.0 before 4.3.0.119, from 4.4.0.0 before 4.4.0.118, from 4.6.0.0 before 4.6.0.105, from 4.7.0.0 before 4.7.0.103.
CVSS Score
7.2
EPSS Score
0.009
Published
2023-02-16
NetModule NSRW web administration interface executes an OS command constructed with unsanitized user input. A successful exploit could allow an authenticated user to execute arbitrary commands with elevated privileges. This issue affects NSRW: from 4.3.0.0 before 4.3.0.119, from 4.4.0.0 before 4.4.0.118, from 4.6.0.0 before 4.6.0.105, from 4.7.0.0 before 4.7.0.103.
CVSS Score
7.2
EPSS Score
0.015
Published
2023-02-16
In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, core path resolution function allocate buffer one byte too small. When resolving paths with lengths close to system MAXPATHLEN setting, this may lead to the byte after the allocated buffer being overwritten with NUL value, which might lead to unauthorized data access or modification.
CVSS Score
7.5
EPSS Score
0.001
Published
2023-02-16
In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, excessive number of parts in HTTP form upload can cause high resource consumption and excessive number of log entries. This can cause denial of service on the affected server by exhausting CPU resources or disk space.
CVSS Score
7.5
EPSS Score
0.001
Published
2023-02-16


Contact Us

Shodan ® - All rights reserved