MidnightBSD

Advisories for cososys

CVE-2014-3932 HIGH

SQL injection vulnerability in the device registration component in wsf/webservice.php in CoSoSys Endpoint Protector 4 4.3.0.4 and 4.4.0.2 allows remote attackers to execute arbitrary SQL commands via unspecified parameters.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-89,

Products Affected

Vendor Product Version
cososys endpoint_protector 4.4.0.2
cososys endpoint_protector 4.3.0.4
CVE-2019-13285 MEDIUM

CoSoSys Endpoint Protector 5.1.0.2 allows Host Header Injection.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N 3.9 3.6

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-74,

Products Affected

Vendor Product Version
cososys endpoint_protector 5.1.0.2