vendor:
Cyclope Employee Surveillance Solution
by:
loneferret
8,8
CVSS
HIGH
Local File Include, SQL Injection, Change Admin account's password
22, 89, 264
CWE
Product Name: Cyclope Employee Surveillance Solution
Affected Version From: 6.1.0
Affected Version To: 6.2.0
Patch Exists: YES
Related CWE: N/A
CPE: a:cyclope-series:cyclope_employee_surveillance_solution:6.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2020
Cyclope Employee Surveillance Solution v6.0
Cyclope Employee Surveillance Solution v6.0 is vulnerable to Local File Include, SQL Injection and Change Admin account's password. Local File Include vulnerability can be exploited by sending a crafted HTTP request containing a maliciously crafted URL to the vulnerable server. SQL Injection vulnerability can be exploited by sending a crafted HTTP request containing maliciously crafted data to the vulnerable server. Change Admin account's password vulnerability can be exploited by sending a crafted HTTP request containing maliciously crafted data to the vulnerable server.
Mitigation:
The user should ensure that all input is validated and filtered before being used in the application. The user should also ensure that the application is running with the least privileges necessary. The user should also ensure that the application is running with the latest security patches and updates.