packetstormsecurity.com
http://packetstormsecurity.com/files/167480/Virtua-Software-Cobranca-12S-SQL-Injection.html CVE-2021-37589
HIGHNuclei
Virtua Software Cobranca 12S - SQLi
Record summary
CVE-2021-37589 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Proofs of concept
1Catalogued exploits
ExploitDBVirtua Software Cobranca 12S - SQLiExploitDB exploitby Luca RegneNot analyzed1 file
Nuclei templates
1ProjectDiscoveryHIGHVirtua Software Cobranca <12R - Blind SQL InjectionCVSS 7.5
Virtua Cobranca before 12R allows blind SQL injection on the login page.
Impact
Successful exploitation of this vulnerability could lead to unauthorized access, data leakage, and potential compromise of the underlying system.
Remediation
Apply the latest patch or update provided by the vendor to fix the SQL Injection vulnerability in Virtua Software Cobranca <12R.
WeaknessesCWE-89
Authorsprincechaddha
Template tagscvecve2021virtuasqlivirtuasoftwarevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:virtuasoftware:cobranca:*:*:*:*:*:*:*:*
Shodan: http.favicon.hash:876876147
FOFA: icon_hash=876876147
https://github.com/luca-regne/my-cves/tree/main/CVE-2021-37589 https://www.virtuasoftware.com.br/ https://www.virtuasoftware.com.br/conteudo.php?content=downloads&lang=pt-br https://nvd.nist.gov/vuln/detail/CVE-2021-37589 https://github.com/luca-regne/public-exploits
Source: ProjectDiscovery
References
4github.com
https://github.com/luca-regne/my-cves/tree/main/CVE-2021-37589 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-37589 virtuasoftware.com.br
https://www.virtuasoftware.com.br/conteudo.php?content=downloads&lang=pt-br