Explore Vulnerabilities SQL Injection Cross-Site Scripting (XSS) Buffer Overflow Denial of Service Remote Code Execution Remote File Include Directory Traversal HTML Injection Stack Overflow Authentication Bypass
by: hyp3rlinx vendor: NAPC Xinet Show More Xinet Elegant 6 Asset Lib Web UI 6.1.655 – SQL Injection The Xinet Elegant 6 Asset Library version 6.1.655 is vulnerable to pre-auth SQL injection. An attacker can exploit this vulnerability to dump tables, usernames, and passwords by manipulating the 'LoginForm[username]' parameter. 6.1 CVSS HIGH SQL Injection 89 CWE Product Name Elegant 6 Asset Library Platforms Tested Affected Version From: 6.1.0655 To: 6.1.0655 2024