Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 3

Количество 3

nvd логотип

CVE-2026-3843

5 месяцев назад

Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL Injection vulnerability (CWE-89) in the system configuration module. A remote attacker can send specially crafted HTTP POST requests to the /php/request.php endpoint via the sql parameter in application/x-www-form-urlencoded data (e.g., action=do&sql=<query_here>&reload_driver=0) to execute arbitrary SQL commands and potentially achieve remote code execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-qw28-fg2g-m9gh

5 месяцев назад

Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL Injection vulnerability (CWE-89) in the system configuration module. A remote attacker can send specially crafted HTTP POST requests to the /php/request.php endpoint via the sql parameter in application/x-www-form-urlencoded data (e.g., action=do&sql=<query_here>&reload_driver=0) to execute arbitrary SQL commands and potentially achieve remote code execution.

CVSS3: 9.8
EPSS: Низкий
fstec логотип

BDU:2026-04518

5 месяцев назад

Уязвимость системы автоматизации АЗС «БУК TS-G», связанная с непринятием мер по защите SQL запроса, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-3843

Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL Injection vulnerability (CWE-89) in the system configuration module. A remote attacker can send specially crafted HTTP POST requests to the /php/request.php endpoint via the sql parameter in application/x-www-form-urlencoded data (e.g., action=do&sql=<query_here>&reload_driver=0) to execute arbitrary SQL commands and potentially achieve remote code execution.

CVSS3: 9.8
1%
Низкий
5 месяцев назад
github логотип
GHSA-qw28-fg2g-m9gh

Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL Injection vulnerability (CWE-89) in the system configuration module. A remote attacker can send specially crafted HTTP POST requests to the /php/request.php endpoint via the sql parameter in application/x-www-form-urlencoded data (e.g., action=do&sql=<query_here>&reload_driver=0) to execute arbitrary SQL commands and potentially achieve remote code execution.

CVSS3: 9.8
1%
Низкий
5 месяцев назад
fstec логотип
BDU:2026-04518

Уязвимость системы автоматизации АЗС «БУК TS-G», связанная с непринятием мер по защите SQL запроса, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 6.8
1%
Низкий
5 месяцев назад

Уязвимостей на страницу