Kwoksys Information Server vulnerabilities
2 known vulnerabilities affecting kwoksys/information_server.
Total CVEs
2
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2013-5028P3MEDIUMCVSS 6.5PoC≤ 2.8.4v2.8.32013-10-11
CVE-2013-5028 [MEDIUM] CWE-89 CVE-2013-5028: SQL injection vulnerability in IT/hardware-list.dll in Kwoksys Kwok Information Server before 2.8.5
SQL injection vulnerability in IT/hardware-list.dll in Kwoksys Kwok Information Server before 2.8.5 allows remote authenticated users to execute arbitrary SQL commands via the (1) hardwareType, (2) hardwareStatus, or (3) hardwareLocation parameter in a search command.
nvd
CVE-2022-45326P4MEDIUMCVSS 4.9fixed in 2.9.5v2.9.52022-12-06
CVE-2022-45326 [MEDIUM] CWE-611 CVE-2022-45326: An XML external entity (XXE) injection vulnerability in Kwoksys Kwok Information Server before v2.9.
An XML external entity (XXE) injection vulnerability in Kwoksys Kwok Information Server before v2.9.5.SP31 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks.
nvd