vendor:
B-swiss 3 Digital Signage System
by:
LiquidWorm
8.8
CVSS
HIGH
Database Disclosure
532
CWE
Product Name: B-swiss 3 Digital Signage System
Affected Version From: 3.6.5
Affected Version To: 3.1.00
Patch Exists: NO
Related CWE: N/A
CPE: a:b-swiss:b-swiss_3_digital_signage_system
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Linux 5.3.0-46-generic x86_64, Linux 4.15.0-20-generic x86_64, Linux 4.9.78-xxxx-std-ipv6-64, Linux 4.7.0-040700-generic x86_64, Linux 4.2.0-27-generic x86_64, Linux 3.19.0-47-generic x86_64, Linux 2.6.32-5-amd64 x86_64, Darwin 17.6.0 root:xnu-4570.61.1~1 x86_64, macOS 10.13.5, Microsoft Windows 7 Business Edition SP1 i586, Apache/2.4.29 (Ubuntu), Apache/2.4.18 (Ubuntu), Apache/2.4.7 (Ubuntu), Apache/2.2.22 (Win64), Apache/2.4.18 (Ubuntu), Apache/2.2.16 (Debian), PHP/7.2.24-0ubuntu0.18.04.6, PHP/5.6.40-26+ubuntu18.04.1+deb.sury.org+1, PHP/5.6.33-1+ubuntu16.04.1+deb.sury.org+1, PHP/5.5.9-1ubuntu4.21, PHP/5.5.9-1ubuntu4.20, PHP/5.5.9-1ubuntu4.19, PHP/5.5.9-1ubuntu4.18, PHP/5.5.9-1ubuntu4.17, PHP/5.5.9-1ubuntu4.16, PHP/5.5.9-1ubuntu4.15, PHP/5.5.9-1ubuntu4.14, PHP/5.5.9-1ubuntu4.13, PHP/5.5.9-1ubuntu4.12, PHP/5.5.9-1ubuntu4.11, PHP/5.5.9-1ubuntu4.10, PHP/5.5.9-1ubuntu4.9, PHP/5.5.9-1ubuntu4.8, PHP/5.5.9-1ubuntu4.7, PHP/5.5.9-1ubuntu4.6, PHP/5.5.9-1ubuntu4.5, PHP/5.5.9-1ubuntu4.4, PHP/5.5.9-1ubuntu4.3, PHP/5.5.9-1ubuntu4.2, PHP/5.5.9-1ubuntu4.1, PHP/5.5.9-1ubuntu4
2020
B-swiss 3 Digital Signage System 3.6.5 – Database Disclosure
The application is vulnerable to unauthenticated database download and information disclosure vulnerability. This can enable the attacker to disclose sensitive information resulting in authentication bypass, session hijacking and full system control.
Mitigation:
Ensure that the application is properly configured to prevent unauthorized access to the database.