Логотип exploitDog
bind:CVE-2020-5725
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-5725

Количество 2

Количество 2

nvd логотип

CVE-2020-5725

почти 6 лет назад

The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpoint. A remote unauthenticated attacker can invoke the login action with a crafted username and, through the use of timing attacks, can discover user passwords.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-m9hp-fm3x-p343

больше 3 лет назад

The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpoint. A remote unauthenticated attacker can invoke the login action with a crafted username and, through the use of timing attacks, can discover user passwords.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-5725

The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpoint. A remote unauthenticated attacker can invoke the login action with a crafted username and, through the use of timing attacks, can discover user passwords.

CVSS3: 5.9
0%
Низкий
почти 6 лет назад
github логотип
GHSA-m9hp-fm3x-p343

The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpoint. A remote unauthenticated attacker can invoke the login action with a crafted username and, through the use of timing attacks, can discover user passwords.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу