Virtua Cobranca是巴西Virtua公司的一种针对呼叫中心以及收款和财务部门的 CRM 软件。 Virtua Cobranca 12R 之前版本存在安全漏洞,该漏洞源于login.php中idusuario参数缺少对于数据的过滤转义。攻击者利用该漏洞可以执行任意SQL语句。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Virtua Cobranca before 12R allows blind SQL injection on the login page. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-37589.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2022-31470 | Axigen Mobile WebMail 跨站脚本漏洞 | |
| CVE-2022-29564 | Jamf Private Access 安全漏洞 | |
| CVE-2022-25361 | WatchGuard Firebox 安全漏洞 | |
| CVE-2022-31495 | LibreHealth EHR 跨站脚本漏洞 | |
| CVE-2022-1708 | CRI-O 资源管理错误漏洞 | |
| CVE-2019-9971 | 3CX Phone 安全漏洞 | |
| CVE-2019-9972 | 3CX Phone 命令注入漏洞 | |
| CVE-2022-29620 | FileZilla 安全漏洞 | |
| CVE-2022-30466 | Joy ebike Wolf 安全漏洞 |
No comments yet