dtssec/CVE-Disclosures

dtssec/CVE-Disclosures

GitHubGitHub
Unavailable
This project is no longer available (or publicly accessible) from GitHub
Releases0
Official Source of public vulnerability disclosures published by DTS Researchers

CVE History

CVEPublishedCVSS v3CVSS v2
9.8 CRITICAL

BluePage CMS thru 3.9 processes an insufficiently sanitized HTTP Header Cookie value allowing MySQL Injection in the 'users-cookie-settings' token using a Time-based blind SLEEP payload.

9.8 CRITICAL

BluePage CMS thru v3.9 processes an insufficiently sanitized HTTP Header allowing MySQL Injection in the 'User-Agent' field using a Time-based blind SLEEP payload.