Ilovewomen

2 exploits Active since Sep 2021
CVE-2021-45232 NOMISEC CRITICAL WRITEUP
Apache Apisix Dashboard < 2.10.1 - Missing Authentication
In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework `droplet` on the basis of framework `gin`, all APIs and authentication middleware are developed based on framework `droplet`, but some API directly use the interface of framework `gin` thus bypassing the authentication.
1 stars
CVSS 9.8
CVE-2021-40655 WRITEUP HIGH WORKING POC
D-LINK-DIR-605 B2 - Info Disclosure
An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page
CVSS 7.5