[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

252416

 
 

909

 
 

196839

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SQL injection vulnerability in Froxlor - CVE-2021-42325 (dpkg)

ID: oval:org.secpod.oval:def:78001Date: (C)2022-03-03   (M)2022-10-10
Class: VULNERABILITYFamily: unix




The host is installed with Froxlor 0.10.28 through 0.10.29.1 and is prone to a SQL injection vulnerability. A flaw is present in the application, which fails to handle an issue in Database/Manager/DbManagerMySQL.php file. Successful exploitation allow attackers to escalate privilege by creating a Froxlor administrator account and use it to execute code remotely as root on the target machine.

Platform:
Linux
Product:
Froxlor
Reference:
CVE-2021-42325
CVE    1
CVE-2021-42325

© SecPod Technologies