Логотип exploitDog
bind:CVE-2021-37413
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-37413

Количество 2

Количество 2

nvd логотип

CVE-2021-37413

больше 3 лет назад

GRANDCOM DynWEB before 4.2 contains a SQL Injection vulnerability in the admin login interface. A remote unauthenticated attacker can exploit this vulnerability to obtain administrative access to the webpage, access the user database, modify web content and upload custom files. The backend login script does not verify and sanitize user-provided strings.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-8h29-88h5-g2w2

больше 3 лет назад

GRANDCOM DynWEB before 4.2 contains a SQL Injection vulnerability in the admin login interface. A remote unauthenticated attacker can exploit this vulnerability to obtain administrative access to the webpage, access the user database, modify web content and upload custom files. The backend login script does not verify and sanitize user-provided strings.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-37413

GRANDCOM DynWEB before 4.2 contains a SQL Injection vulnerability in the admin login interface. A remote unauthenticated attacker can exploit this vulnerability to obtain administrative access to the webpage, access the user database, modify web content and upload custom files. The backend login script does not verify and sanitize user-provided strings.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-8h29-88h5-g2w2

GRANDCOM DynWEB before 4.2 contains a SQL Injection vulnerability in the admin login interface. A remote unauthenticated attacker can exploit this vulnerability to obtain administrative access to the webpage, access the user database, modify web content and upload custom files. The backend login script does not verify and sanitize user-provided strings.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад

Уязвимостей на страницу