Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Max Segura

#15510de 53,635
17.5CVSS total
Vulnerabilidades · 2
Alta
1
Crítica
1
PT-2019-12253
10
2019-05-09
Engenius · Engenius Ews660Ap · CVE-2019-11353
**Name of the Vulnerable Software and Affected Versions** EnGenius EWS660AP version 2.0.284 **Description** The issue allows an attacker to execute arbitrary commands using the built-in `ping` and `traceroute` utilities by injecting multiple parameters with different payloads. **Recommendations** For EnGenius EWS660AP version 2.0.284, update to a later firmware version to resolve the issue.
PT-2018-14056
7.5
2018-10-03
Multitech · Multitech Faxfinder · CVE-2018-17562
**Name of the Vulnerable Software and Affected Versions** Multi-Tech FaxFinder versions prior to 5.1.6 **Description** The issue allows an attacker to perform SQL Injection via the "status/call details?oid=" URI, enabling them to extract the underlying database schema and potentially disclose other fax server information through different injection points. **Recommendations** For versions prior to 5.1.6, update to version 5.1.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the "status/call details?oid=" URI to minimize the risk of exploitation.