This repository contains information and proofs of concept (PoCs) for the CVEs I have found.
1. EasyVirt
CVE ID | Vulnerabilty | Product |
---|---|---|
CVE-2024-53354 | Multiple SQL Injection | DCScope <= 8.6.0 / Co2Scope <= 1.3.0 |
CVE-2024-53355 | Broken Access Control | DCScope <= 8.6.0 / Co2Scope <= 1.3.0 |
CVE-2024-53356 | Weak JWT Secret | DCScope <= 8.6.0 / Co2Scope <= 1.3.0 |
CVE-2024-53357 | Sensitive Data Exposure | DCScope <= 8.6.0 / Co2Scope <= 1.3.0 |
CVE-2024-55062 | Remote Code Execution (Unauthenticated) | DCScope <= 8.6.0 / Co2Scope <= 1.3.0 |
CVE-2024-57587 | Multiple SQL Injection (Unauthenticated) | DCScope <= 8.6.0 / Co2Scope <= 1.3.0 |
CVE-2024-55064 | Multiple Stored XSS | DC NetScope <= 8.6.4 |
2. GreaterWMS
CVE ID | Vulnerabilty | Product |
---|---|---|
CVE-2025-26201 | Authentication Bypass via Credential Disclosure | GreaterWMS <= 2.1.49 |