mirror of
https://github.com/0xMarcio/cve.git
synced 2025-11-30 18:56:19 +00:00
24 lines
1.0 KiB
Markdown
24 lines
1.0 KiB
Markdown
### [CVE-2024-44349](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-44349)
|
|

|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
A SQL injection vulnerability in login portal in AnteeoWMS before v4.7.34 allows unauthenticated attackers to execute arbitrary SQL commands via the username parameter and disclosure of some data in the underlying DB.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://blog.cybergon.com/posts/cve-2024-44349/
|
|
- https://github.com/AndreaF17/PoC-CVE-2024-44349
|
|
|
|
#### Github
|
|
- https://github.com/20142995/nuclei-templates
|
|
- https://github.com/AndreaF17/PoC-CVE-2024-44349
|
|
- https://github.com/cyb3r-w0lf/nuclei-template-collection
|
|
- https://github.com/fkie-cad/nvd-json-data-feeds
|
|
- https://github.com/nomi-sec/PoC-in-GitHub
|
|
|