Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Hackping

#13555of 53,608
19.6Total CVSS
Vulnerabilities · 2
Critical
2
PT-2018-12517
9.8
2018-07-20
Cckevincyh Ssh · Companywebsite · CVE-2018-14440
**Name of the Vulnerable Software and Affected Versions** cckevincyh SSH CompanyWebsite versions through 2018-05-03 **Description** An issue exists in the software, allowing SQL injection via the `noticeInfo` parameter in the "admin/noticeManageAction queryNotice.action" endpoint. **Recommendations** For versions through 2018-05-03, avoid using the `noticeInfo` parameter in the "admin/noticeManageAction queryNotice.action" endpoint until the issue is resolved.
PT-2018-12518
9.8
2018-07-20
Ssh Company · Cckevincyh Ssh Companywebsite · CVE-2018-14441
**Name of the Vulnerable Software and Affected Versions** cckevincyh SSH CompanyWebsite through 2018-05-03 **Description** An issue was discovered that allows arbitrary file upload. This is demonstrated by uploading a .jsp file with the `content type` set to `image/jpeg`. The upload is possible through the "admin/admin/fileUploadAction fileUpload.action" endpoint. **Recommendations** For versions through 2018-05-03, consider restricting access to the "fileUploadAction fileUpload.action" endpoint to minimize the risk of exploitation. As a temporary workaround, avoid using the file upload feature until a fix is available. At the moment, there is no information about a newer version that contains a fix for this issue.