Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-14328

Опубликовано: 23 июл. 2018
Источник: nvd
CVSS3: 9.8
CVSS2: 5
EPSS Средний

Описание

Brynamics "Online Trade - Online trading and cryptocurrency investment system" allows remote attackers to obtain sensitive information via a direct request for /dashboard/addplan, /dashboard/paywithcard/charge, /dashboard/withdrawal, or /privacy&terms, as demonstrated by reading database username, database password, database_name, and IP address fields, related to CVE-2018-12908.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:brynamics:online_trade:-:*:*:*:*:*:*:*

EPSS

Процентиль: 95%
0.19886
Средний

9.8 Critical

CVSS3

5 Medium

CVSS2

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

Brynamics "Online Trade - Online trading and cryptocurrency investment system" allows remote attackers to obtain sensitive information via a direct request for /dashboard/addplan, /dashboard/paywithcard/charge, /dashboard/withdrawal, or /privacy&terms, as demonstrated by reading database username, database password, database_name, and IP address fields, related to CVE-2018-12908.

EPSS

Процентиль: 95%
0.19886
Средний

9.8 Critical

CVSS3

5 Medium

CVSS2

Дефекты

CWE-200