Логотип exploitDog
bind:CVE-2018-4056
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-4056

Количество 5

Количество 5

ubuntu логотип

CVE-2018-4056

около 7 лет назад

An exploitable SQL injection vulnerability exists in the administrator web portal function of coTURN prior to version 4.5.0.9. A login message with a specially crafted username can cause an SQL injection, resulting in authentication bypass, which could give access to the TURN server administrator web portal. An attacker can log in via the external interface of the TURN server to trigger this vulnerability.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2018-4056

около 7 лет назад

An exploitable SQL injection vulnerability exists in the administrator web portal function of coTURN prior to version 4.5.0.9. A login message with a specially crafted username can cause an SQL injection, resulting in authentication bypass, which could give access to the TURN server administrator web portal. An attacker can log in via the external interface of the TURN server to trigger this vulnerability.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2018-4056

около 7 лет назад

An exploitable SQL injection vulnerability exists in the administrator ...

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-c3pf-948r-8592

больше 3 лет назад

An exploitable SQL injection vulnerability exists in the administrator web portal function of coTURN prior to version 4.5.0.9. A login message with a specially crafted username can cause an SQL injection, resulting in authentication bypass, which could give access to the TURN server administrator web portal. An attacker can log in via the external interface of the TURN server to trigger this vulnerability.

CVSS3: 9.8
EPSS: Низкий
fstec логотип

BDU:2020-03293

больше 8 лет назад

Уязвимость функции сервера coTURN, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2018-4056

An exploitable SQL injection vulnerability exists in the administrator web portal function of coTURN prior to version 4.5.0.9. A login message with a specially crafted username can cause an SQL injection, resulting in authentication bypass, which could give access to the TURN server administrator web portal. An attacker can log in via the external interface of the TURN server to trigger this vulnerability.

CVSS3: 9.8
0%
Низкий
около 7 лет назад
nvd логотип
CVE-2018-4056

An exploitable SQL injection vulnerability exists in the administrator web portal function of coTURN prior to version 4.5.0.9. A login message with a specially crafted username can cause an SQL injection, resulting in authentication bypass, which could give access to the TURN server administrator web portal. An attacker can log in via the external interface of the TURN server to trigger this vulnerability.

CVSS3: 9.8
0%
Низкий
около 7 лет назад
debian логотип
CVE-2018-4056

An exploitable SQL injection vulnerability exists in the administrator ...

CVSS3: 9.8
0%
Низкий
около 7 лет назад
github логотип
GHSA-c3pf-948r-8592

An exploitable SQL injection vulnerability exists in the administrator web portal function of coTURN prior to version 4.5.0.9. A login message with a specially crafted username can cause an SQL injection, resulting in authentication bypass, which could give access to the TURN server administrator web portal. An attacker can log in via the external interface of the TURN server to trigger this vulnerability.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
fstec логотип
BDU:2020-03293

Уязвимость функции сервера coTURN, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 9.8
0%
Низкий
больше 8 лет назад

Уязвимостей на страницу