Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.126744
Category:General
Title:MyConnection Server 11.3c < 11.3d Multiple Vulnerabilities
Summary:MyConnection Server is prone to multiple vulnerabilities.
Description:Summary:
MyConnection Server is prone to multiple vulnerabilities.

Vulnerability Insight:
The following vulnerabilities exist:

- CVE-2023-42032: MyConnection Server allows to information disclosure within the
doRTAAccessUPass, an exposed dangerous method. Attacker can leverage this vulnerability to
disclose information in the context of the application.

- CVE-2023-42033: Due to the improper restriction of XML External Entity (XXE) references, a
crafted document specifying an URI causes the XML parser to access the URI and embed the contents
back into the XML document for further processing. An attacker can use this vulnerability to
disclose information in the context of root.

- CVE-2023-42034: MyConnection Server allows to authentication bypass within the
doRTAAccessCTConfig method. The issue results from the lack of proper validation of user-supplied
data, which can lead to the injection of an arbitrary script. An attacker can leverage this
vulnerability to bypass authentication on the system.

- CVE-2023-42035: MyConnection Server allows to remote code execution (RCE) within the
doPostUploadfiles method. The issue results from the lack of proper validation of a user-supplied
path prior to using it in file operations. An attacker can leverage this vulnerability to execute
code in the context of root.

Affected Software/OS:
MyConnection Server version 11.3c prior to 11.3d

Solution:
Update to version 11.3d or later.

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2023-42032
ZDI-23-1398
https://www.zerodayinitiative.com/advisories/ZDI-23-1398/
vendor-provided URL
https://myconnectionserver.visualware.com/support/security-advisories
Common Vulnerability Exposure (CVE) ID: CVE-2023-42033
ZDI-23-1396
https://www.zerodayinitiative.com/advisories/ZDI-23-1396/
Common Vulnerability Exposure (CVE) ID: CVE-2023-42034
ZDI-23-1399
https://www.zerodayinitiative.com/advisories/ZDI-23-1399/
Common Vulnerability Exposure (CVE) ID: CVE-2023-42035
ZDI-23-1397
https://www.zerodayinitiative.com/advisories/ZDI-23-1397/
CopyrightCopyright (C) 2024 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.