github.com
https://github.com/awillix/research/blob/main/cve/CVE-2021-30175.md CVE-2021-30175
CRITICALNuclei
ZEROF Web Server 1.0 - SQL Injection
Record summary
CVE-2021-30175 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
ZEROF Web Server 1.0 (April 2021) allows SQL Injection via the /HandleEvent endpoint for the login page.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryCRITICALZEROF Web Server 1.0 - SQL InjectionCVSS 9.8
ZEROF Web Server 1.0 (April 2021) allows SQL Injection via the /HandleEvent endpoint for the login page.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.
Remediation
Apply the latest security patches or updates provided by the vendor to fix the SQL Injection vulnerability in ZEROF Web Server 1.0.
WeaknessesCWE-89
Authorsedoardottt
Template tagscve2021cvezerofsqlivuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:zerof:web_server:1.0:*:*:*:*:*:*:*
Shodan: cpe:"cpe:2.3:a:google:web_server"
https://github.com/awillix/research/blob/main/cve/CVE-2021-30175.md https://pro.zerof.ru/ https://github.com/awillix/research https://nvd.nist.gov/vuln/detail/CVE-2021-30175
Source: ProjectDiscovery
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-30175 pro.zerof.ru
https://pro.zerof.ru/