Логотип exploitDog
bind:CVE-2023-36284
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-36284

Количество 2

Количество 2

nvd логотип

CVE-2023-36284

больше 2 лет назад

An unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameter date_from, date_to, and id_product allows a remote attacker to bypass a web application's authentication and authorization mechanisms and retrieve the contents of an entire database.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-33vr-wwjf-63w6

больше 2 лет назад

An unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameter date_from, date_to, and id_product allows a remote attacker to bypass a web application's authentication and authorization mechanisms and retrieve the contents of an entire database.

CVSS3: 7.5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-36284

An unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameter date_from, date_to, and id_product allows a remote attacker to bypass a web application's authentication and authorization mechanisms and retrieve the contents of an entire database.

CVSS3: 7.5
24%
Средний
больше 2 лет назад
github логотип
GHSA-33vr-wwjf-63w6

An unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameter date_from, date_to, and id_product allows a remote attacker to bypass a web application's authentication and authorization mechanisms and retrieve the contents of an entire database.

CVSS3: 7.5
24%
Средний
больше 2 лет назад

Уязвимостей на страницу