[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2018-4056 -- coturn

ID: oval:org.secpod.oval:def:1901912Date: (C)2019-04-29   (M)2022-06-07
Class: VULNERABILITYFamily: unix




An exploitable SQL injection vulnerability exists in the administrator web portal function of coTURN prior to version 4.5.0.9. A login message with a specially crafted username can cause an SQL injection, resulting in authentication bypass, which could give access to the TURN server administrator web portal. An attacker can log in via the external interface of the TURN server to trigger this vulnerability.

Platform:
Ubuntu 19.04
Product:
coturn
Reference:
CVE-2018-4056
CVE    1
CVE-2018-4056
CPE    2
cpe:/o:ubuntu:ubuntu_linux:19.04
cpe:/a:github:coturn

© SecPod Technologies