CVE-2022-26959
- EPSS 0.23%
- Veröffentlicht 16.09.2022 02:15:08
- Zuletzt bearbeitet 21.11.2024 06:54:52
There are two full (read/write) Blind/Time-based SQL injection vulnerabilities in the Northstar Club Management version 6.3 application. The vulnerabilities exist in the userName parameter of the processlogin.jsp page in the /northstar/Portal/ direct...
CVE-2021-29398
- EPSS 1.11%
- Veröffentlicht 04.02.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:01:02
Directory traversal in /northstar/Common/NorthFileManager/fileManagerObjects.jsp Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to browse and list the directories across the entire filesystem of the host ...
- EPSS 14.16%
- Veröffentlicht 04.02.2022 19:15:07
- Zuletzt bearbeitet 21.11.2024 06:01:01
Remote Code Execution in cominput.jsp and comoutput.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to inject and execute arbitrary system commands via the unsanitized user-controlled "command" and ...
CVE-2021-29394
- EPSS 0.15%
- Veröffentlicht 04.02.2022 19:15:07
- Zuletzt bearbeitet 21.11.2024 06:01:02
Account Hijacking in /northstar/Admin/changePassword.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote authenticated users to change the password of any targeted user accounts via lack of proper authorization in the user-c...
CVE-2021-29395
- EPSS 1.17%
- Veröffentlicht 04.02.2022 19:15:07
- Zuletzt bearbeitet 21.11.2024 06:01:02
Directory travesal in /northstar/filemanager/download.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to download arbitrary files, including JSP source code, across the filesystem of the host of the...
CVE-2021-29396
- EPSS 1.4%
- Veröffentlicht 04.02.2022 19:15:07
- Zuletzt bearbeitet 21.11.2024 06:01:02
Systemic Insecure Permissions in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to use various functionalities without authentication.
CVE-2021-29397
- EPSS 0.18%
- Veröffentlicht 04.02.2022 19:15:07
- Zuletzt bearbeitet 21.11.2024 06:01:02
Cleartext Transmission of Sensitive Information in /northstar/Admin/login.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote local user to intercept users credentials transmitted in cleartext over HTTP.