hundanchen69/cve

hundanchen69/cve

Releases0
Stars1

CVE History

CVEPublishedCVSS v3CVSS v2
6.3 MEDIUM6.5 MEDIUM

A vulnerability classified as critical was found in Netentsec NS-ASG Application Security Gateway 6.3. This vulnerability affects unknown code of the file /admin/add_ikev2.php. The manipulation of the argument TunnelId leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-259714 is the identifier assigned to this vulnerability.

9.8 CRITICAL

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/edit_virtual_site_info.php.

6.3 MEDIUM

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /WebPages/history.php.

8.8 HIGH

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /3g/index.php.

5.3 MEDIUM

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/configguide/ipsec_guide_1.php.

8.8 HIGH

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/export_excel_user.php.

8.8 HIGH

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/config_ISCGroupSSLCert.php.

9.8 CRITICAL

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/edit_fire_wall.php.

5.4 MEDIUM

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /3g/menu.php.

9.8 CRITICAL

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/edit_user_login.php.

6.3 MEDIUM

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/config_ISCGroupTimePolicy.php.

5.1 MEDIUM

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /include/authrp.php.

8.8 HIGH

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /WebPages/applyhardware.php.

8.8 HIGH

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/address_interpret.php.

9.8 CRITICAL

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/add_getlogin.php.

6.3 MEDIUM6.5 MEDIUM

A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been rated as critical. Affected by this issue is some unknown functionality of the file /protocol/firewall/addfirewall.php. The manipulation of the argument FireWallTableArray leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-257282 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.