Total
6 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-38538 | 1 Archerydms | 1 Archery | 2022-11-21 | N/A | 9.8 CRITICAL |
Archery v1.7.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the checksum parameter in the report module. | |||||
CVE-2022-38537 | 1 Archerydms | 1 Archery | 2022-11-07 | N/A | 9.8 CRITICAL |
Archery v1.4.5 to v1.8.5 was discovered to contain multiple SQL injection vulnerabilities via the start_file, end_file, start_time, and stop_time parameters in the binlog2sql interface. | |||||
CVE-2022-38541 | 1 Archerydms | 1 Archery | 2022-11-07 | N/A | 9.8 CRITICAL |
Archery v1.8.3 to v1.8.5 was discovered to contain multiple SQL injection vulnerabilities via the start_time and stop_time parameters in the my2sql interface. | |||||
CVE-2022-38540 | 1 Archerydms | 1 Archery | 2022-10-16 | N/A | 9.8 CRITICAL |
Archery v1.4.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the ThreadIDs parameter in the create_kill_session interface. | |||||
CVE-2022-38542 | 1 Archerydms | 1 Archery | 2022-10-06 | N/A | 9.8 CRITICAL |
Archery v1.4.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the ThreadIDs parameter in the kill_session interface. The project has released an update, please upgrade to v1.9.0 and above. | |||||
CVE-2022-38539 | 1 Archerydms | 1 Archery | 2022-10-06 | N/A | 9.8 CRITICAL |
Archery v1.7.5 to v1.8.5 was discovered to contain a SQL injection vulnerability via the where parameter at /archive/apply. |