Hyperkopite/Roothub_vulns

Hyperkopite/Roothub_vulns

Releases0

CVE History

CVEPublishedCVSS v3CVSS v2
8 HIGH6 MEDIUM

Directory Traversal vulnerability in file cn/roothub/store/FileSystemStorageService in function store in Roothub 2.6.0 allows remote attackers with low privlege to arbitrarily upload files via /common/upload API, which could lead to remote arbitrary code execution.

9.8 CRITICAL7.5 HIGH

SQL injection vulnerability in Topics Counting feature of Roothub 2.6.0 allows unauthorized attackers to execute arbitrary SQL commands via the "s" parameter remotely.

9.8 CRITICAL7.5 HIGH

SQL injection vulnerability in Topics Searching feature of Roothub 2.6.0 allows unauthorized attackers to execute arbitrary SQL commands via the "s" parameter remotely.