Verypdf docPrint Pro 8
Description
Verypdf docPrint Pro 8
Remediation
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Search and filter 17874 vulnerabilities with AI analyst insights
Verypdf docPrint Pro 8
Verypdf docPrint Pro 8
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Easy File Sharing Web Server 7
Easy File Sharing Web Server 7
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Web Ofisi Rent a Car v3 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL...
Web Ofisi Rent a Car v3 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'klima' parameter
Apply vendor patches immediately. Review database access controls and enable query logging.
Web Ofisi Platinum E-Ticaret v5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by inject...
Web Ofisi Platinum E-Ticaret v5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'q' parameter
Apply vendor patches immediately. Review database access controls and enable query logging.
Web Ofisi Platinum E-Ticaret v5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by inject...
Web Ofisi Platinum E-Ticaret v5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'q' GET parameter
---METADATA---
VENDOR: Web Ofisi
PRODUCT: Platinum E-Ticaret
AFFECTED_VERSIONS: v5
---END_METADATA---
Description Summary:
Web Ofisi Platinum E-Ticaret v5 is vulnerable to an unauthenticated SQL injection via the 'q' GET parameter, allowing for unauthorized database manipulation.
Executive Summary:
The 'q' parameter in Web Ofisi Platinum E-Ticaret v5 is vulnerable to unauthenticated SQL injection, risking the exposure of sensitive e-commerce data.
Vulnerability Details
CVE-ID: CVE-2019-25460
Affected Software: Web Ofisi Platinum E-Ticaret
Affected Versions: v5
Vulnerability: The application's search or query function, utilizing the 'q' GET parameter, fails to sanitize input. This allows an unauthenticated attacker to inject SQL code to extract data from the database.
Business Impact
For an e-commerce platform, this vulnerability could lead to the theft of customer lists, order history, and potentially payment metadata. The CVSS score of 8.2 indicates a high severity that requires immediate attention to protect consumer trust.
Remediation Plan
Immediate Action: Apply the vendor's security patch for version v5 immediately to sanitize the 'q' parameter.
Proactive Monitoring: Monitor for automated scanning tools that frequently target search parameters with common SQL injection payloads.
Compensating Controls: Implement a WAF to block requests to the 'q' parameter that contain illegal characters or SQL keywords.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of February 23, 2026, there is no public information indicating active exploitation. This vulnerability is part of a larger set of disclosures affecting Web Ofisi products.
Analyst Recommendation
E-commerce applications are high-value targets. Organizations using the Platinum E-Ticaret v5 platform should apply the patch immediately and verify that all user-supplied inputs are handled using prepared statements or parameterized queries.
Apply vendor patches immediately. Review database access controls and enable query logging.
Web Ofisi Emlak V2 contains multiple SQL injection vulnerabilities in the endpoint that allow unauthenticated attackers to manipulate database queries...
Web Ofisi Emlak V2 contains multiple SQL injection vulnerabilities in the endpoint that allow unauthenticated attackers to manipulate database queries through GET parameters
---METADATA---
VENDOR: Web Ofisi
PRODUCT: Emlak
AFFECTED_VERSIONS: V2
---END_METADATA---
Description Summary:
Web Ofisi Emlak V2 contains multiple SQL injection vulnerabilities in its endpoints, allowing unauthenticated attackers to manipulate database queries via GET parameters.
Executive Summary:
Multiple unauthenticated SQL injection points in Web Ofisi Emlak V2 present a high risk of total database compromise by remote attackers.
Vulnerability Details
CVE-ID: CVE-2019-25459
Affected Software: Web Ofisi Emlak
Affected Versions: V2
Vulnerability: This vulnerability involves several distinct endpoints where GET parameters are not properly sanitized. An unauthenticated attacker can use these multiple vectors to inject SQL commands and gain unauthorized database access.
Business Impact
The presence of multiple injection points increases the likelihood of a successful breach. Attackers could leak sensitive information or destroy database records, leading to severe operational disruption. The CVSS score of 8.2 justifies an urgent response.
Remediation Plan
Immediate Action: Update the software to the latest patched version immediately. Ensure all endpoints mentioned in the vendor advisory are addressed.
Proactive Monitoring: Enable comprehensive database auditing to track all administrative actions and unusual query volumes.
Compensating Controls: Use a WAF to provide virtual patching for the affected endpoints until the software can be fully updated.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of February 23, 2026, there is no public information indicating active exploitation. The discovery of multiple flaws in a single version indicates a systemic failure in input validation.
Analyst Recommendation
Given the multiple attack vectors, a comprehensive patching strategy is required. Administrators should not only apply the current fix but also perform a broader security review of the application's input handling to prevent similar issues.
Apply vendor patches immediately. Review database access controls and enable query logging.
Web Ofisi Firma Rehberi v1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting S...
Web Ofisi Firma Rehberi v1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through GET parameters
---METADATA---
VENDOR: Web Ofisi
PRODUCT: Firma Rehberi
AFFECTED_VERSIONS: v1
---END_METADATA---
Description Summary:
Web Ofisi Firma Rehberi v1 is vulnerable to an unauthenticated SQL injection through various GET parameters, allowing attackers to manipulate database queries.
Executive Summary:
An unauthenticated SQL injection vulnerability in Web Ofisi Firma Rehberi v1 allows remote attackers to compromise the confidentiality and integrity of the system's database.
Vulnerability Details
CVE-ID: CVE-2019-25458
Affected Software: Web Ofisi Firma Rehberi
Affected Versions: v1
Vulnerability: Multiple GET parameters in the application are susceptible to SQL injection. An unauthenticated attacker can craft malicious URLs to execute arbitrary SQL commands against the backend database.
Business Impact
Exploitation could lead to the total exposure of the firm directory database, including sensitive contact and business information. The High severity rating (CVSS 8.2) reflects the ease of exploitation and the significant impact on data privacy.
Remediation Plan
Immediate Action: Apply the official security patches from Web Ofisi immediately to remediate the vulnerable GET parameters.
Proactive Monitoring: Monitor web server logs for suspicious GET requests containing SQL keywords like SELECT, UNION, or DROP.
Compensating Controls: Implement input validation at the application level and use a WAF to filter out malicious SQL patterns in URL strings.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of February 23, 2026, there is no public information indicating active exploitation. This late disclosure highlights the need for ongoing legacy software audits.
Analyst Recommendation
IT teams must prioritize patching this vulnerability, as SQL injection via GET parameters is one of the most frequently exploited web flaws. Failure to secure these inputs could result in a significant data breach with minimal effort from an attacker.
Apply vendor patches immediately. Review database access controls and enable query logging.
Web Ofisi Firma v13 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code...
Web Ofisi Firma v13 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'oz' array parameter
---METADATA---
VENDOR: Web Ofisi
PRODUCT: Firma
AFFECTED_VERSIONS: v13
---END_METADATA---
Description Summary:
Web Ofisi Firma v13 contains an unauthenticated SQL injection vulnerability via the 'oz' array parameter, allowing for the manipulation of backend database queries.
Executive Summary:
Web Ofisi Firma v13 is susceptible to an unauthenticated SQL injection attack that could lead to a complete compromise of the application's database.
Vulnerability Details
CVE-ID: CVE-2019-25457
Affected Software: Web Ofisi Firma
Affected Versions: v13
Vulnerability: The application processes the 'oz' array parameter without sufficient sanitization. An unauthenticated attacker can inject malicious SQL code through this parameter to bypass security controls and interact directly with the database.
Business Impact
The potential for data theft and unauthorized modification of company records is high. With a CVSS score of 8.2, this vulnerability poses a substantial threat to any organization relying on this software for firm management or directory services.
Remediation Plan
Immediate Action: Immediately apply the vendor-provided patches for Web Ofisi Firma v13 to secure the 'oz' parameter processing logic.
Proactive Monitoring: Regularly audit database logs for evidence of SQL syntax errors or unauthorized table access attempts.
Compensating Controls: Deploy or configure a Web Application Firewall (WAF) to detect and block array-based SQL injection attempts.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of February 23, 2026, there is no public information indicating active exploitation. However, the use of array parameters for injection is a known technique that may bypass basic security filters.
Analyst Recommendation
The unauthenticated nature of this SQL injection makes it a critical target for automated exploitation scripts. We recommend that administrators verify their current version and apply necessary updates immediately to prevent data loss or unauthorized access.
Apply vendor patches immediately. Review database access controls and enable query logging.
Web Ofisi Emlak v2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code...
Web Ofisi Emlak v2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'ara' GET parameter
---METADATA---
VENDOR: Web Ofisi
PRODUCT: Emlak
AFFECTED_VERSIONS: v2
---END_METADATA---
Description Summary:
Web Ofisi Emlak v2 is vulnerable to an unauthenticated SQL injection via the 'ara' GET parameter, enabling attackers to manipulate database queries.
Executive Summary:
Unauthenticated attackers can exploit a High-severity SQL injection vulnerability in Web Ofisi Emlak v2 to access or modify sensitive database records.
Vulnerability Details
CVE-ID: CVE-2019-25456
Affected Software: Web Ofisi Emlak
Affected Versions: v2
Vulnerability: The 'ara' GET parameter in Web Ofisi Emlak v2 is not properly sanitized before being used in database queries. This allows an unauthenticated attacker to execute arbitrary SQL code.
Business Impact
A successful attack could result in the full exposure of real estate listings, user credentials, and internal configuration data. The CVSS score of 8.2 highlights the significant risk to business continuity and data confidentiality.
Remediation Plan
Immediate Action: Update to a patched version of Web Ofisi Emlak v2 or follow the vendor's specific remediation guidance immediately.
Proactive Monitoring: Implement query logging to identify suspicious database interactions and monitor for unexpected data export activities.
Compensating Controls: Restrict access to the search functionality using a WAF to block requests containing special characters used in SQL injection attacks.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of February 23, 2026, there is no public information indicating active exploitation. As a late-disclosure vulnerability, it is possible that scanning tools already include checks for this flaw.
Analyst Recommendation
Organizations using Web Ofisi Emlak v2 must treat this as a high-priority security issue. The ability for an unauthenticated attacker to manipulate the database remotely necessitates the immediate application of patches or the implementation of strict input validation controls.
Apply vendor patches immediately. Review database access controls and enable query logging.
Web Ofisi E-Ticaret v3 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL c...
Web Ofisi E-Ticaret v3 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'a' parameter
---METADATA---
VENDOR: Web Ofisi
PRODUCT: E-Ticaret
AFFECTED_VERSIONS: v3
---END_METADATA---
Description Summary:
Web Ofisi E-Ticaret v3 contains an unauthenticated SQL injection vulnerability in the 'a' parameter, allowing for unauthorized database manipulation.
Executive Summary:
An unauthenticated SQL injection vulnerability in Web Ofisi E-Ticaret v3 puts the entire backend database at risk of unauthorized access and data exfiltration.
Vulnerability Details
CVE-ID: CVE-2019-25455
Affected Software: Web Ofisi E-Ticaret
Affected Versions: v3
Vulnerability: The application fails to properly sanitize input provided through the 'a' parameter. This allows an unauthenticated remote attacker to inject SQL commands directly into the database query logic.
Business Impact
This vulnerability allows for the unauthorized disclosure of sensitive customer data and potential administrative takeover. Given the CVSS score of 8.2, this represents a High-risk flaw that could lead to significant reputational damage and legal liabilities following a data breach.
Remediation Plan
Immediate Action: Apply the security patches provided by Web Ofisi immediately. If the software is end-of-life, consider migrating to a supported e-commerce platform.
Proactive Monitoring: Review database access logs for high-frequency queries or syntax errors that indicate automated SQL injection scanning.
Compensating Controls: Utilize a Web Application Firewall (WAF) to inspect incoming GET and POST requests for common SQL injection signatures.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of February 23, 2026, there is no public information indicating active exploitation of this vulnerability. This is a late-disclosure entry, suggesting the flaw may have existed in the wild for a significant period.
Analyst Recommendation
Due to the unauthenticated nature of this vulnerability and its direct impact on database security, immediate remediation is required. Administrators should prioritize patching or implementing robust perimeter defenses to prevent attackers from exploiting this well-known vulnerability class.
Apply vendor patches immediately. Review database access controls and enable query logging.
phpMoAdmin 1
phpMoAdmin 1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Dolibarr ERP/CRM 10
Dolibarr ERP/CRM 10
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Dolibarr ERP/CRM 10
Dolibarr ERP/CRM 10
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
DIGIT CENTRIS ERP contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code t...
DIGIT CENTRIS ERP contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the datum1, datum2, KID, and PID parameters
Apply vendor patches immediately. Review database access controls and enable query logging.
Fiverr Clone Script 1
Fiverr Clone Script 1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Inventory Webapp contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code th...
Inventory Webapp contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through GET parameters
Apply vendor patches immediately. Review database access controls and enable query logging.
Web Wiz Forums 12
Web Wiz Forums 12
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Thesystem 1.0 contains a command injection vulnerability in the run_command endpoint, allowing unauthenticated attackers to execute arbitrary system c...
Thesystem 1.0 contains a command injection vulnerability in the run_command endpoint, allowing unauthenticated attackers to execute arbitrary system commands via POST requests.
---METADATA---
VENDOR: thesystem
PRODUCT: thesystem
AFFECTED_VERSIONS: 1.0
---END_METADATA---
Description Summary:
Thesystem 1.0 contains a command injection vulnerability in the run_command endpoint, allowing unauthenticated attackers to execute arbitrary system commands via POST requests.
Executive Summary:
A critical command injection vulnerability in "thesystem" allows unauthenticated remote attackers to execute arbitrary code and gain full control of the affected server.
Vulnerability Details
CVE-ID: CVE-2019-25441
Affected Software: thesystem
Affected Versions: 1.0
Vulnerability: This is a classic command injection flaw within the run_command endpoint. The application accepts shell commands directly from the command parameter in POST requests without any authentication or sanitization, allowing for immediate remote code execution.
Business Impact
The impact is a total loss of confidentiality, integrity, and availability. An attacker can execute any command with the permissions of the web server, leading to data exfiltration, malware installation, or pivoting into the internal network. The CVSS score of 9.8 highlights the extreme risk associated with this unauthenticated exploit.
Remediation Plan
Immediate Action: Disable the run_command endpoint immediately or update the software to a version that removes this functionality or implements strict authentication and parameterization.
Proactive Monitoring: Review system logs for suspicious shell activity and monitor the web server for unauthorized POST requests to the run_command endpoint.
Compensating Controls: Implement a Web Application Firewall (WAF) to block requests containing shell metacharacters and restrict network access to the server.
Exploitation Status
Public Exploit Available: No
Analyst Notes: This is a late disclosure of a 2019 vulnerability. While there is no current evidence of active exploitation, the simplicity of the attack makes it a primary target for legacy system scanning.
Analyst Recommendation
The existence of an unauthenticated command execution endpoint is a massive security failure. Administrators must decommission version 1.0 of "thesystem" or apply immediate restrictive controls to prevent total server compromise.
Update thesystem Multiple Products to the latest version. Check vendor security advisory for specific patch details. Monitor for exploitation attempts and review access logs.
WebIncorp ERP contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code throu...
WebIncorp ERP contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the prod_id parameter
Apply vendor patches immediately. Review database access controls and enable query logging.
NoviSmart CMS contains an SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious code throug...
NoviSmart CMS contains an SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious code through the Referer HTTP header field
---METADATA---
VENDOR: NoviSmart
PRODUCT: CMS
AFFECTED_VERSIONS: See vendor advisory for specific affected versions
---END_METADATA---
Description Summary:
NoviSmart CMS is vulnerable to a high-severity SQL injection via the Referer HTTP header, allowing remote attackers to execute arbitrary SQL queries against the database.
Executive Summary:
A critical SQL injection vulnerability in NoviSmart CMS allows remote attackers to gain unauthorized access to the underlying database, potentially leading to a complete data breach.
Vulnerability Details
CVE-ID: CVE-2019-25439
Affected Software: NoviSmart CMS
Affected Versions: See vendor advisory for specific affected versions
Vulnerability: This is an SQL injection vulnerability where the application fails to properly sanitize input from the Referer HTTP header. A remote attacker can inject malicious SQL code through this header to manipulate database queries without requiring prior authentication.
Business Impact
A successful SQL injection attack can result in the total compromise of the CMS database, including the theft of user credentials, sensitive corporate content, and customer data. The CVSS score of 8.2 underscores the high risk, as it allows for unauthorized data exfiltration and potential administrative takeover of the website.
Remediation Plan
Immediate Action: Apply the vendor-provided security patches immediately. If a patch is unavailable, the affected code must be manually updated to use parameterized queries.
Proactive Monitoring: Enable comprehensive database query logging and monitor for unusual syntax or high volumes of errors associated with the Referer header.
Compensating Controls: Deploy or configure a Web Application Firewall (WAF) to inspect and block malicious SQL patterns specifically within the HTTP Referer header field.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of February 23, 2026, there is no public information indicating active exploitation of this vulnerability. This is a late disclosure of a 2019 flaw, which often means automated scanning tools may already be looking for unpatched legacy systems.
Analyst Recommendation
The ability to execute arbitrary SQL queries remotely makes this a high-priority threat. Organizations must verify their NoviSmart CMS version and apply all available security updates immediately to prevent catastrophic data loss.
Apply vendor patches immediately. Review database access controls and enable query logging.
LabCollector 5
LabCollector 5
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Sricam DeviceViewer 3
Sricam DeviceViewer 3
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
SpotAuditor 5
SpotAuditor 5
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
XOOPS CMS 2
XOOPS CMS 2
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Part-DB 0
Part-DB 0
---METADATA---
VENDOR: Part-DB
PRODUCT: Part-DB
AFFECTED_VERSIONS: Part-DB 0.x (See vendor advisory for specific versions)
---END_METADATA---
Description Summary:
A late-disclosure vulnerability in the legacy Part-DB 0.x inventory management system could allow for unauthorized data manipulation or access.
Executive Summary:
A high-severity vulnerability in legacy versions of Part-DB poses a significant risk to the integrity of inventory data and system security.
Vulnerability Details
CVE-ID: CVE-2019-25432
Affected Software: Part-DB
Affected Versions: Part-DB 0
Vulnerability: This is a late-disclosure vulnerability affecting the legacy "0" branch of Part-DB. While specific technical details are sparse, the CVSS score of 7.5 suggests a significant flaw, likely involving insecure data handling or authentication bypass in the legacy codebase.
Business Impact
A successful exploit could lead to the loss or corruption of critical inventory data, impacting manufacturing or supply chain operations. Because this affects a legacy version, the risk is compounded by the potential lack of ongoing support and the age of the underlying technology stack.
Remediation Plan
Immediate Action: Organizations still running Part-DB 0.x should immediately migrate to the modern, supported version of Part-DB or apply any available legacy patches.
Proactive Monitoring: Review database logs for unauthorized modifications to inventory records or suspicious administrative logins.
Compensating Controls: Isolate the Part-DB server from the internet and limit access to a small number of authorized users on the internal network.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of February 22, 2026, there is no public information indicating active exploitation. This late disclosure highlights the ongoing risk of maintaining legacy software that is no longer receiving regular security audits.
Analyst Recommendation
Running legacy software like Part-DB 0.x is a significant security risk. We strongly recommend migrating to a modern, actively maintained version of the software to ensure continued protection against both known and emerging vulnerabilities.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
delpino73 Blue-Smiley-Organizer 1
delpino73 Blue-Smiley-Organizer 1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Comodo Dome Firewall 2
Comodo Dome Firewall 2
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Bematech (formerly Logic Controls, now Elgin) MP-4200 TH printer contains a denial of service vulnerability in the admin configuration page
Bematech (formerly Logic Controls, now Elgin) MP-4200 TH printer contains a denial of service vulnerability in the admin configuration page
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Smoothwall Express 3
Smoothwall Express 3
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Smoothwall Express 3
Smoothwall Express 3
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Ashop Shopping Cart Software contains a time-based blind SQL injection vulnerability that allows attackers to manipulate database queries through the...
Ashop Shopping Cart Software contains a time-based blind SQL injection vulnerability that allows attackers to manipulate database queries through the blacklistitemid parameter
Apply vendor patches immediately. Review database access controls and enable query logging.
Smoothwall Express 3
Smoothwall Express 3
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
microASP Portal+ CMS contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malic...
microASP Portal+ CMS contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code into the explode_tree parameter
---METADATA---
VENDOR: microASP
PRODUCT: Portal+ CMS
AFFECTED_VERSIONS: See vendor advisory for specific affected versions
---END_METADATA---
Description Summary:
An unauthenticated SQL injection vulnerability in microASP Portal+ CMS allows remote attackers to execute arbitrary SQL queries via the explode_tree parameter.
Executive Summary:
The microASP Portal+ CMS is susceptible to a high-severity SQL injection attack that allows unauthenticated users to access or delete sensitive database information.
Vulnerability Details
CVE-ID: CVE-2019-25366
Affected Software: microASP Portal+ CMS
Affected Versions: See vendor advisory for specific affected versions
Vulnerability: This vulnerability is a classic SQL injection flaw located in the "explode_tree" parameter. Because the application does not validate this input, an unauthenticated remote attacker can submit crafted SQL commands to be executed by the database server.
Business Impact
With a CVSS score of 8.2, the impact of this vulnerability is severe. An attacker could bypass all authentication mechanisms, extract the entire user database, or modify website content, leading to significant financial loss and long-term reputational damage for the organization.
Remediation Plan
Immediate Action: Update the microASP Portal+ CMS to the latest version immediately. Ensure the patch specifically addresses input validation for the explode_tree parameter.
Proactive Monitoring: Organizations should audit their database logs for any suspicious activity targeting the explode_tree parameter and review for any unauthorized administrative account creation.
Compensating Controls: Use a Web Application Firewall (WAF) to filter out SQL injection strings in GET and POST requests to the affected CMS.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of February 23, 2026, there is no public information indicating active exploitation of this vulnerability. This late-disclosed 2019 vulnerability remains dangerous as it targets a specific, named parameter that is easy for attackers to scan for.
Analyst Recommendation
Because this vulnerability is unauthenticated and provides direct database access, it must be treated with the highest urgency. Immediate patching is required to secure the environment against automated exploitation attempts.
Apply vendor patches immediately. Review database access controls and enable query logging.
A buffer overflow in ChaosPro 2.0's configuration file handling allows attackers to gain remote code execution on Windows XP systems by overwriting th...
A buffer overflow in ChaosPro 2.0's configuration file handling allows attackers to gain remote code execution on Windows XP systems by overwriting the Structured Exception Handler (SEH).
---METADATA---
VENDOR: ChaosPro
PRODUCT: ChaosPro
AFFECTED_VERSIONS: 2.0
---END_METADATA---
Description Summary:
A buffer overflow in ChaosPro 2.0's configuration file handling allows attackers to gain remote code execution on Windows XP systems by overwriting the Structured Exception Handler (SEH).
Executive Summary:
ChaosPro 2.0 is vulnerable to a critical buffer overflow that allows attackers to execute arbitrary code via a malicious configuration file, posing a severe risk to legacy Windows systems.
Vulnerability Details
CVE-ID: CVE-2019-25365
Affected Software: ChaosPro
Affected Versions: 2.0
Vulnerability: A stack-based buffer overflow exists in the way ChaosPro handles configuration file paths. By crafting a malformed configuration file, an unauthenticated attacker can overwrite the Structured Exception Handler (SEH) to gain remote code execution.
Business Impact
Successful exploitation allows an attacker to run arbitrary code with the same privileges as the logged-in user. On legacy systems like Windows XP, this often leads to full system compromise. The CVSS score of 9.8 highlights the critical nature of this memory corruption flaw.
Remediation Plan
Immediate Action: Update ChaosPro to the latest version. If updates are unavailable for this legacy software, consider migrating to a modern, supported fractal generator.
Proactive Monitoring: Monitor for application crashes and review system logs for signs of SEH-based exploitation attempts, such as unusual memory access patterns.
Compensating Controls: Implement Software Restriction Policies (SRP) or AppLocker to prevent the execution of unauthorized files and ensure that configuration files are only sourced from trusted locations.
Exploitation Status
Public Exploit Available: No
Analyst Notes: As of Feb 18, 2026, there is no public information indicating active exploitation. This is a late disclosure affecting legacy environments, which are often more susceptible to such binary exploits.
Analyst Recommendation
While this vulnerability primarily impacts legacy systems, the risk of code execution remains critical. Organizations still utilizing ChaosPro 2.0 should move to a secure alternative or apply vendor-provided patches immediately to secure their environments.
Update the configuration Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
A buffer overflow in the POP3 USER command handling in MailCarrier 2.51 allows remote attackers to execute arbitrary code by sending an oversized buff...
A buffer overflow in the POP3 USER command handling in MailCarrier 2.51 allows remote attackers to execute arbitrary code by sending an oversized buffer to the service.
---METADATA---
VENDOR: MailCarrier
PRODUCT: MailCarrier
AFFECTED_VERSIONS: 2.51
---END_METADATA---
Description Summary:
A buffer overflow in the POP3 USER command handling in MailCarrier 2.51 allows remote attackers to execute arbitrary code by sending an oversized buffer to the service.
Executive Summary:
MailCarrier 2.51 is susceptible to a critical remote buffer overflow vulnerability that allows unauthenticated attackers to gain full system access via the POP3 service.
Vulnerability Details
CVE-ID: CVE-2019-25364
Affected Software: MailCarrier
Affected Versions: 2.51
Vulnerability: The POP3 service in MailCarrier fails to check the bounds of the input provided to the USER command. An unauthenticated remote attacker can send a specially crafted, oversized buffer to overwrite system memory and execute arbitrary code.
Business Impact
An attacker can gain unauthorized access to the mail server, allowing them to read, delete, or spoof emails, as well as use the server as a platform for further internal network attacks. The CVSS score of 9.8 indicates a critical risk to the organization's communication infrastructure.
Remediation Plan
Immediate Action: Patch MailCarrier to the latest version or replace the software with a modern, secure mail server implementation.
Proactive Monitoring: Monitor network traffic for unusually long strings sent to the POP3 port (typically port 110) and review service logs for unexpected restarts or crashes.
Compensating Controls: Use an Intrusion Prevention System (IPS) to detect and drop POP3 packets containing excessively long arguments for the USER command.
Exploitation Status
Public Exploit Available: No
Analyst Notes: As of Feb 18, 2026, there is no public information indicating active exploitation. However, POP3 services are frequently scanned, and buffer overflows in such services are prime targets for reliable exploitation.
Analyst Recommendation
The ability for an unauthenticated attacker to execute code on a mail server is a critical threat. Organizations must prioritize either patching MailCarrier or migrating to a more secure and actively maintained mail server platform immediately.
Update the POP3 Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
WMV to AVI MPEG DVD WMV Convertor 4
WMV to AVI MPEG DVD WMV Convertor 4
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A stack-based buffer overflow in the license handling fields of this video converter allows attackers to execute arbitrary code via a 6000-byte malici...
A stack-based buffer overflow in the license handling fields of this video converter allows attackers to execute arbitrary code via a 6000-byte malicious payload.
---METADATA---
VENDOR: WMV to AVI MPEG DVD WMV Convertor
PRODUCT: WMV to AVI MPEG DVD WMV Convertor
AFFECTED_VERSIONS: 4.6.1217
---END_METADATA---
Description Summary:
A stack-based buffer overflow in the license handling fields of this video converter allows attackers to execute arbitrary code via a 6000-byte malicious payload.
Executive Summary:
A critical buffer overflow vulnerability in WMV to AVI MPEG DVD WMV Convertor allows attackers to execute arbitrary code and gain remote access via a bind shell.
Vulnerability Details
CVE-ID: CVE-2019-25362
Affected Software: WMV to AVI MPEG DVD WMV Convertor
Affected Versions: 4.6.1217
Vulnerability: The application fails to properly validate the length of input in the license name and license code fields. By providing a 6000-byte payload, an unauthenticated attacker can trigger a stack-based buffer overflow to gain remote code execution.
Business Impact
Exploitation allows for the deployment of a bind shell on port 4444, providing the attacker with direct command-line access to the affected system. With a CVSS score of 9.8, this vulnerability poses a severe risk to data integrity and system security, potentially leading to unauthorized data exfiltration or malware installation.
Remediation Plan
Immediate Action: Discontinue use of the affected software version and update to the latest available release from the vendor.
Proactive Monitoring: Monitor for unexpected listening ports, specifically TCP port 4444, and review system logs for application crashes related to the converter software.
Compensating Controls: Use host-based intrusion prevention systems (HIPS) to block unauthorized bind shells and restrict the application's ability to interact with sensitive system memory.
Exploitation Status
Public Exploit Available: No
Analyst Notes: As of Feb 18, 2026, there is no public information indicating active exploitation of this vulnerability. This is a late disclosure of an older flaw, but the technical risk remains high for legacy systems still running this software.
Analyst Recommendation
This vulnerability represents a classic but highly effective attack vector for remote system compromise. IT administrators should immediately identify any instances of this software in their environment and apply the necessary updates or decommission the software to prevent exploitation.
Update Unknown Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
A buffer overflow in the Ayukov NFTP client's SYST command handling allows remote attackers to execute arbitrary code on the client machine via a craf...
A buffer overflow in the Ayukov NFTP client's SYST command handling allows remote attackers to execute arbitrary code on the client machine via a crafted server response.
---METADATA---
VENDOR: Ayukov
PRODUCT: NFTP client
AFFECTED_VERSIONS: 1.71
---END_METADATA---
Description Summary:
A buffer overflow in the Ayukov NFTP client's SYST command handling allows remote attackers to execute arbitrary code on the client machine via a crafted server response.
Executive Summary:
The Ayukov NFTP client is vulnerable to a critical buffer overflow that allows a malicious FTP server to execute arbitrary code on the connecting user's system.
Vulnerability Details
CVE-ID: CVE-2019-25361
Affected Software: Ayukov NFTP client
Affected Versions: 1.71
Vulnerability: The client fails to properly validate the size of the response received from an FTP server for the SYST command. A remote attacker controlling a malicious server can send an oversized payload to trigger a buffer overflow and execute a bind shell on port 5150.
Business Impact
Exploitation leads to a full compromise of the workstation running the NFTP client. This can result in the theft of sensitive local files, credential harvesting, or the installation of persistent malware. The CVSS score of 9.8 underscores the severe risk to the client system.
Remediation Plan
Immediate Action: Update the NFTP client to a patched version or switch to a modern, secure FTP client that implements proper buffer management.
Proactive Monitoring: Monitor for unexpected network listeners on port 5150 and audit outgoing FTP connections to untrusted or unknown external servers.
Compensating Controls: Utilize endpoint detection and response (EDR) tools to identify and block the execution of unauthorized shells and unusual memory writes originating from the NFTP process.
Exploitation Status
Public Exploit Available: No
Analyst Notes: As of Feb 18, 2026, there is no public information indicating active exploitation. This late disclosure highlights the danger of using unmaintained legacy networking tools.
Analyst Recommendation
Client-side vulnerabilities are particularly dangerous as they can bypass perimeter defenses. Users should immediately cease using affected versions of the NFTP client and migrate to a secure alternative to prevent remote code execution.
Update the SYST Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
Aida64 Engineer contains a buffer overflow in its CSV logging configuration that allows attackers to execute arbitrary code via a malformed log file u...
Aida64 Engineer contains a buffer overflow in its CSV logging configuration that allows attackers to execute arbitrary code via a malformed log file using SEH overwrite techniques.
---METADATA---
VENDOR: Aida64
PRODUCT: Aida64 Engineer
AFFECTED_VERSIONS: 6.10.5200
---END_METADATA---
Description Summary:
Aida64 Engineer contains a buffer overflow in its CSV logging configuration that allows attackers to execute arbitrary code via a malformed log file using SEH overwrite techniques.
Executive Summary:
A critical buffer overflow in Aida64 Engineer allows attackers to achieve remote code execution on a victim's system by tricking them into processing a malicious CSV log file.
Vulnerability Details
CVE-ID: CVE-2019-25360
Affected Software: Aida64 Engineer
Affected Versions: 6.10.5200
Vulnerability: The application is vulnerable to a stack-based buffer overflow when parsing malformed CSV logging configurations. An attacker can craft a malicious file that utilizes Structured Exception Handler (SEH) overwrite techniques to hijack the execution flow and run arbitrary code.
Business Impact
Successful exploitation results in the complete compromise of the system running the Aida64 software. This is particularly concerning for "Engineer" editions, which are often used by IT staff with elevated privileges, potentially leading to broader network exposure. The CVSS score is 9.8.
Remediation Plan
Immediate Action: Update Aida64 Engineer to the latest version immediately. Avoid opening or importing configuration/log files from untrusted or external sources.
Proactive Monitoring: Monitor for unusual application behavior or crashes when handling CSV files and use EDR tools to detect memory-based exploitation attempts.
Compensating Controls: Implement file integrity monitoring (FIM) for configuration directories and ensure that the application is running with the least privilege necessary.
Exploitation Status
Public Exploit Available: No
Analyst Notes: As of Feb 18, 2026, there is no public information indicating active exploitation. This vulnerability relies on a user interacting with a malicious file, making social engineering a likely delivery vector.
Analyst Recommendation
Given the potential for high-privilege code execution, administrators must ensure that all installations of Aida64 are updated. Users should be cautioned against importing any configuration files that have not been verified.
Update the CSV Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
SD
SD
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
FileOptimizer 14
FileOptimizer 14
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Control Center PRO 6
Control Center PRO 6
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
gSOAP 2
gSOAP 2
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
iSmartViewPro 1
iSmartViewPro 1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Foscam Video Management System 1
Foscam Video Management System 1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Crystal Live HTTP Server 6
Crystal Live HTTP Server 6
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Centova Cast 3
Centova Cast 3
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
XMedia Recode 3
XMedia Recode 3
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
ScadaApp for iOS 1
ScadaApp for iOS 1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
thesystem App 1
thesystem App 1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
---METADATA---
VENDOR: Web Ofisi
PRODUCT: Rent a Car
AFFECTED_VERSIONS: v3
---END_METADATA---
Description Summary:
Web Ofisi Rent a Car v3 contains an unauthenticated SQL injection vulnerability in the 'klima' parameter, allowing attackers to execute arbitrary SQL commands.
Executive Summary:
An unauthenticated SQL injection vulnerability in Web Ofisi Rent a Car v3 allows remote attackers to manipulate the backend database, threatening data confidentiality.
Vulnerability Details
CVE-ID: CVE-2019-25462
Affected Software: Web Ofisi Rent a Car
Affected Versions: v3
Vulnerability: The 'klima' parameter in the Rent a Car v3 application is not properly validated. An unauthenticated attacker can exploit this to inject malicious SQL code directly into the application's database queries.
Business Impact
Successful exploitation could allow an attacker to view, modify, or delete rental records and customer information. The High severity (CVSS 8.2) reflects the potential for significant data loss and unauthorized access to business-critical information.
Remediation Plan
Immediate Action: Immediately apply the security patches provided by Web Ofisi for the Rent a Car v3 application.
Proactive Monitoring: Audit database logs for unusual activity related to the rental listing tables and monitor for SQL error spikes.
Compensating Controls: Deploy a WAF to filter out malicious SQL injection attempts targeting the 'klima' parameter.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of February 23, 2026, there is no public information indicating active exploitation. This late disclosure suggests that legacy systems may still be at risk.
Analyst Recommendation
The ability for an unauthenticated user to interact with the database is a critical security failure. We strongly recommend immediate patching and a review of the application's overall security posture to ensure no other parameters are similarly exposed.