CVE-2022-41391 OcoMon v4.0 had a SQL injection vulnerability in the cod parameter of showImg.php.
An attacker can inject malicious SQL code into the cod parameter to run arbitrary SQL commands. This may lead to the disclosure of user data
CVE-2022-41475 An attacker can add an administrator account via a CSRF in RPCMS v3.0.2.
This vulnerability does not affect most users, only those who create new accounts on the target site. This could be significant for a site with
CVE-2022-41407 The App v1.0 had a SQL injection vulnerability via the id parameter.
A user with a low privilege level (e.g., guest) could potentially exploit this vulnerability and inject SQL code to gain higher privileges. A SQL
CVE-2022-39015 BOE AdminTools/SDK can access information which would be restricted with certain conditions.
The information accessed by an attacker depends on what information is stored in the user database and how the data is stored. User information may
CVE-2022-41195 Memory management issues can lead to EAAmiga Interchange File Format files being opened by victims and resulting in a Remote Code Execution.
This vulnerability can be exploited by hackers to get remote code execution on the system of the victim as it is a part of SAP
Episode
00:00:00
00:00:00