M3@ZionLab from DBAppSecurity

2 exploits Active since Jul 2019
CVE-2019-13373 METASPLOIT CRITICAL ruby WORKING POC
Dlink Central Wifimanager - SQL Injection
An issue was discovered in the D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6. Input does not get validated and arbitrary SQL statements can be executed in the database via the /web/Public/Conn.php parameter dbSQL.
CVSS 9.8
CVE-2019-13372 METASPLOIT CRITICAL ruby WORKING POC
Dlink Central Wifimanager < 1.03 - Code Injection
/web/Lib/Action/IndexAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to execute arbitrary PHP code via a cookie because a cookie's username field allows eval injection, and an empty password bypasses authentication.
CVSS 9.8