Security Vulnerabilities
- CVEs Published In 2018
SRCMS 3.0.0 allows CSRF via admin.php?m=Admin&c=gifts&a=update to change goods prices with the super administrator's privileges.
Point Of Sales 1.0 allows SQL injection via the login screen, related to LoginForm1.vb.
School Equipment Monitoring System 1.0 allows SQL injection via the login screen, related to include/user.vb.
An issue was discovered in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3. It does not taint strings that result from unpacking tainted strings with some formats.
K-iwi Framework 1775 has SQL Injection via the admin/user/group/update user_group_id parameter or the admin/user/user/update user_id parameter.
Local Server 1.0.9 has a Buffer Overflow via crafted data on Port 4008.
Modbus Slave 7.0.0 in modbus tools has a Buffer Overflow.
RhinOS 3.0 build 1190 allows CSRF.
SaltOS 3.1 r8126 allows action=login&querystring=&user=[SQL] SQL Injection.
SaltOS 3.1 r8126 allows action=ajax&query=numbers&page=usuarios&action2=[SQL] SQL Injection.