CVE-2024-8174
published 2024-08-26CVE-2024-8174: A vulnerability has been found in code-projects Blood Bank System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality…
PriorityP430medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.55%
42.2th percentile
A vulnerability has been found in code-projects Blood Bank System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /login.php of the component Login Page. The manipulation of the argument user leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| blood_bank_system_project | blood_bank_system | — | — |
| code-projects | blood_bank_system | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
ET EXPLOIT CVE-2018-8174 Common Construct B64 M3
suricata·2019-03-11·CVSS 7.5
CVE-2018-8174 [HIGH] ET EXPLOIT CVE-2018-8174 Common Construct B64 M3
ET EXPLOIT CVE-2018-8174 Common Construct B64 M3
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT CVE-2018-8174 Common Construct B64 M3"; flow:established,to_client; file.data; content:"|6f5532686c6247786a6232526c5157526b636c4268636d4674|"; classtype:attempted-user; sid:2027071; rev:2; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, attack_target Client_Endpoint, created_at 2019_03_11, cve CVE_2018_8174, deployment Perimeter, performance_impact Moderate, signature_severity Major, tag CISA_KEV, updated_at 2024_03_14;)
Suricata
ET EXPLOIT CVE-2018-8174 Common Construct B64 M1
suricata·2019-03-11·CVSS 7.5
CVE-2018-8174 [HIGH] ET EXPLOIT CVE-2018-8174 Common Construct B64 M1
ET EXPLOIT CVE-2018-8174 Common Construct B64 M1
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT CVE-2018-8174 Common Construct B64 M1"; flow:established,to_client; file.data; content:"|4b464e6f5a5778735932396b5a55466b5a484a5159584a6862|"; classtype:attempted-user; sid:2027069; rev:3; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, attack_target Client_Endpoint, created_at 2019_03_11, cve CVE_2018_8174, deployment Perimeter, performance_impact Moderate, signature_severity Major, tag CISA_KEV, updated_at 2024_03_14;)
Suricata
ET EXPLOIT CVE-2018-8174 Common Construct B64 M2
suricata·2019-03-11·CVSS 7.5
CVE-2018-8174 [HIGH] ET EXPLOIT CVE-2018-8174 Common Construct B64 M2
ET EXPLOIT CVE-2018-8174 Common Construct B64 M2
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT CVE-2018-8174 Common Construct B64 M2"; flow:established,to_client; file.data; content:"|68546147567362474e765a4756425a475279554746795957|"; classtype:attempted-user; sid:2027070; rev:2; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, attack_target Client_Endpoint, created_at 2019_03_11, cve CVE_2018_8174, deployment Perimeter, performance_impact Moderate, signature_severity Major, tag CISA_KEV, updated_at 2024_03_14;)
No public exploits indexed.
No writeups or analysis indexed.
2024-08-26
Published