RSS   Vulnerabilities for 'Ssh companywebsite'   RSS

2018-07-19
 
CVE-2018-14441

CWE-434
 

 
An issue was discovered in cckevincyh SSH CompanyWebsite through 2018-05-03. admin/admin/fileUploadAction_fileUpload.action allows arbitrary file upload, as demonstrated by a .jsp file with the image/jpeg content type.

 
 
CVE-2018-14440

CWE-89
 

 
An issue was discovered in cckevincyh SSH CompanyWebsite through 2018-05-03. SQL injection exists via the admin/noticeManageAction_queryNotice.action noticeInfo parameter.

 


Copyright 2024, cxsecurity.com

 

Back to Top