May 5, 2023Jedox 2020.2.5 Database Credential Disclosure

Jedox version 2020.2.5 suffers from having improper access controls in /tc/rpc that allows remote authenticated users to view details of database connections via the class com.jedox.etl.mngr.Connections and the method getGlobalConnection.

May 5, 2023Jedox 2020.2.5 Groovy-Scripts Remote Code Execution

The Jedox Integrator in Jedox version 2020.2.5 allows remote authenticated users to create Jobs to execute arbitrary code via Groovy-scripts.

May 5, 2023Jedox 2020.2.5 Configurable Storage Path Remote Code Execution

Jedox version 2020.2.5 suffers from a remote code execution vulnerability via the configurable storage path.

May 5, 2023Jedox 2020.2.5 Cross Site Scripting

Jedox version 2020.2.5 has a persistent cross site scripting vulnerability that allows remote authenticated users to inject arbitrary web scripts or HTML in the logs page via the log module.

May 5, 2023Jedox 2022.4.2 Directory Traversal / Remote Code Execution

Jedox version 2022.4.2 has a directory traversal vulnerability in /be/erpc.php allows remote authenticated users to execute arbitrary code.

May 5, 2023Jedox 2022.4.2 RPC Interface Remote Code Execution

Jedox version 2022.4.2 has a vulnerability in /be/rpc.php and /be/erpc.php that allows remote authenticated users to load arbitrary PHP classes from the rtn directory and to execute its methods.

May 4, 2023Shannon Baseband fmtp SDP Attribute Memory Corruption

Shannon Baseband suffers from a memory corruption vulnerability that occurs when the baseband modem processes SDP when setting up a call. When an fmtp attribute is parsed, the integer that represents the payload type is copied into an 8-byte buffer using

May 4, 2023Companymaps 8.0 SQL Injection

Companymaps version 8.0 suffers from a remote SQL injection vulnerability.

May 3, 2023Databricks Platform Cluster Isolation Bypass

The Databricks Platform as of 2023-01-26 suffered from a cluster isolation bypass vulnerability through insecure defaults and shared storage.

May 3, 2023SoftExpert Suite 2.1.3 Local File Inclusion

SoftExpert Suite version 2.1.3 suffers from a local file inclusion vulnerability.

Archives
Categories
  • All Exploits 4122
  • Remote Code Execution
  • SQL Injection
  • Command Injection
  • Local File Inclusion
  • Cross Site Scripting
  • Privilege Escalation
  • Denial Of Service
  • Authentication Bypass
  • Buffer Overflow