CVE-2023-34635
Summary
| CVE | CVE-2023-34635 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-07-31 14:15:00 UTC |
| Updated | 2023-08-04 18:52:00 UTC |
| Description | Wifi Soft Unibox Administration 3.0 and 3.1 is vulnerable to SQL Injection. The vulnerability occurs because of not validating or sanitizing the user input in the username field of the login page. |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Wifi-soft | Unibox Administration | 3.0 | All | All | All |
| Application | Wifi-soft | Unibox Administration | 3.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Wifi Soft Unibox Administration 3.0 / 3.1 SQL Injection ≈ Packet Storm | MISC | packetstormsecurity.com | |
| Wifi Soft Unibox Administration 3.0 & 3.1 - SQL Injection - PHP webapps Exploit | MISC | www.exploit-db.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.