A vulnerability exists in GE Proficy HMI/SCADA CIMPLICITY 8.2 which allows an attacker to gain elevated privileges by exploiting the SERVICE_CHANGE_CONFIG privilege. The exploit code is written in C and uses the system() function to execute a malicious payload which changes the binary path of the CimProxy service to a malicious executable. The malicious executable is then executed with SYSTEM privileges.
KpwinSQL suffers from an unauthenticated file inclusion vulnerability (LFI) when input passed thru the 'lang' parameter to the following scripts which are not properly verified: index.php, help.php, logpin.php, brow.php, indexs.php, search.php, hledani.php, hled_hesl.php before being used to include files. This can be exploited to include files from local resources with their absolute path and with directory traversal attacks. Moreover, KpwinSQL system suffers from Cross Site Scripting vulnerability when input passed thru the 'vyhl' parameter to 'index.php' script which does not perform input validation.
Several XSS vulnerabilities have been found on several pages of the administration panel. Reflected XSS may lead to session hijacking on admin user.
GNU Wget before 1.18 when supplied with a malicious URL (to a malicious or compromised web server) can be tricked into saving an arbitrary remote file supplied by an attacker, with arbitrary contents and filename under the current directory and possibly other directories by writing to .wgetrc. Depending on the context in which wget is used, this can lead to remote code execution and even root privilege escalation if wget is run via a root cronjob as is often the case in many web application deployments. The vulnerability could also be exploited by well-positioned attackers within the network who are able to intercept/modify the network traffic.
This module exploits an SQL injection, auth bypass, file upload, command injection, and privilege escalation in Nagios XI <= 5.2.7 to pop a root shell.
AWBS suffers from multiple SQL Injection vulnerabilities. Input passed via the 'cat' and 'so' GET parameters are not properly sanitised before being returned to the user or used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. Multiple cross-site scripting vulnerabilities were also discovered. The issue is triggered when input passed via multiple parameters is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.
A non-privileged authenticated user can inject SQL commands on the <base-url>/24online/webpages/myaccount/usersessionsummary.jsp?invoiceid=<numeric-id> &fromdt=dd/mm/yyyy hh:mm:ss&todt= dd/mm/yyyy hh:mm:ss. There is complete informational disclosure over the stored database.
DocuClass is a modular and scalable enterprise content management (ECM) solution that allows organizations to streamline internal operations by significantly improving the way they manage their information within a business process. An unauthenticated attacker can read or modify data in the application database, execute code, and compromise the host system. An unauthenticated user can access stored documents by directly calling the document url. An unauthenticated attacker can execute malicious scripts in the user's browser.
eCardMAX suffers from a SQL Injection vulnerability. Input passed via the 'row_number' GET parameter is not properly sanitised before being returned to the user or used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. Multiple cross-site scripting vulnerabilities were also discovered. The issue is triggered when input passed via multiple parameters is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.
WebCalendar attempts to uses the HTTP Referer to check that requests are originating from same server. However, the application fails to check the Referer header when performing certain actions such as adding, deleting or modifying events. An attacker can craft a malicious link and send it to the victim, tricking them into performing actions without their knowledge.