Prisma Industriale Checkweigher PrismaWEB是意大利Prisma公司的一套用于检重称的管理系统。 Prisma Industriale Checkweigher PrismaWEB 1.21版本中存在安全漏洞。远程攻击者可通过读取user/scripts/login_par.js文件利用该漏洞获取prismaweb账户的硬编码密码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | PrismaWEB is susceptible to credential disclosure. The vulnerability exists due to the disclosure of hard-coded credentials allowing an attacker to effectively bypass authentication of PrismaWEB with administrator privileges. The credentials can be disclosed by simply navigating to the login_par.js JavaScript page that holds the username and password for the management interface that are being used via the Login() function in /scripts/functions_cookie.js script. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2018/CVE-2018-9161.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2018-8893 | Z-BlogPHP 跨站请求伪造漏洞 | |
| CVE-2018-8908 | Frog CMS 跨站请求伪造漏洞 | |
| CVE-2018-9162 | Contec Smart Home 安全漏洞 | |
| CVE-2015-9258 | Docker Notary 安全漏洞 | |
| CVE-2015-9259 | Docker Notary 安全漏洞 | |
| CVE-2018-9159 | Spark 安全漏洞 | |
| CVE-2018-9160 | SickRage 安全漏洞 | |
| CVE-2017-18255 | Linux kernel 安全漏洞 |
No comments yet