Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.103976
Category:Web application abuses
Title:Kloxo SQLi and RCE Vulnerability
Summary:Kloxo is prone to SQL injection (SQLi) and remote code execution; (RCE) vulnerabilities.
Description:Summary:
Kloxo is prone to SQL injection (SQLi) and remote code execution
(RCE) vulnerabilities.

Vulnerability Insight:
The vulnerability is in /lbin/webcommand.php where the parameter
login-name is not properly sanitized and allow a SQL Injection.

Vulnerability Impact:
An unauthenticated remote attacker can retrieve data from the database
like e.g. the admin cleartext password and might use this for further attacks like
code execution in the Command Center function.

Affected Software/OS:
LxCenter Kloxo Version 6.1.12 and possible prior.

Solution:
Upgrade to version 6.1.13 or higher.

CVSS Score:
8.5

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:P/A:N

CopyrightCopyright (C) 2014 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.