Showing 2 vulnerabilities on this page for Data Center Audit

Signals CISA KEV Ransomware Nuclei
Sourceforge vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Data Center Audit 2.6.2 SQL Injection via username Parameter

Data Center Audit 2.6.2 contains an SQL injection vulnerability in the username parameter of dca_login.php that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can submit crafted SQL payloads through POST requests to extract sensitive database information including usernames, database names, and version details.

CWE-89Mar 6, 2026
CVSS8.8v4.0EPSS0.237%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Data Center Audit 2.6.2 Cross-Site Request Forgery via dca_resetpw.php

Data Center Audit 2.6.2 contains a cross-site request forgery vulnerability that allows attackers to reset administrator passwords without authentication by submitting crafted POST requests. Attackers can send requests to dca_resetpw.php with parameters updateuser, pass, pass2, and submit_reset to change the admin account password and gain administrative access.

CWE-352Mar 6, 2026
CVSS6.9v4.0EPSS0.125%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX