Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Alex Lauerman

Pesquisador deTrustFoundry
#17900de 53,635
15CVSS total
Vulnerabilidades · 2
Alta
2
PT-2015-7292
7.5
2015-12-27
Epiphany · Epiphany Cardio Server · CVE-2015-6537
**Name of the Vulnerable Software and Affected Versions** Epiphany Cardio Server version 3.3 **Description** The issue allows remote attackers to execute arbitrary SQL commands via a crafted URL, specifically through a SQL injection vulnerability in the login page. **Recommendations** For Epiphany Cardio Server version 3.3, update to a version that includes a fix for the SQL injection vulnerability in the login page, or as a temporary workaround, consider restricting access to the login page to minimize the risk of exploitation.
PT-2015-7293
7.5
2015-12-27
Epiphany · Epiphany Cardio Server · CVE-2015-6538
**Name of the Vulnerable Software and Affected Versions** Epiphany Cardio Server versions 3.3 through 4.1 **Description** The issue concerns the mishandling of authentication requests on the login page, allowing remote attackers to conduct LDAP injection attacks. This enables attackers to bypass intended access restrictions by using a crafted URL. **Recommendations** For versions 3.3 through 4.1, consider temporarily restricting access to the login page until a patch is available. As a mitigation measure, restrict the use of LDAP authentication to minimize the risk of exploitation.