Lucene search

K

Cayin Technology Security Vulnerabilities

cve
cve

CVE-2020-7357

Cayin CMS suffers from an authenticated OS semi-blind command injection vulnerability using default credentials. This can be exploited to inject and execute arbitrary shell commands as the root user through the 'NTP_Server_IP' HTTP POST parameter in system.cgi page. This issue affects several...

9.9CVSS

9.7AI Score

0.959EPSS

2020-08-06 04:15 PM
68
cve
cve

CVE-2020-7356

CAYIN xPost suffers from an unauthenticated SQL Injection vulnerability. Input passed via the GET parameter 'wayfinder_seqid' in wayfinder_meeting_input.jsp is not properly sanitized before being returned to the user or used in SQL queries. This can be exploited to manipulate SQL queries by...

10CVSS

9.9AI Score

0.032EPSS

2020-08-06 04:15 PM
69