6.9

CVSS4.0

CVE-2025-59746 - Multiple vulnerabilities in AndSoft's e-TMS

Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them a malicious URL.Β The relationship between parameter and assigned identifier isΒ 'm' parameter in '/lib/asp/alert.asp'.

πŸ“… Published: Oct. 2, 2025, 2:20 p.m. πŸ”„ Last Modified: Oct. 2, 2025, 7:45 p.m.

6.9

CVSS4.0

CVE-2025-59745 - Multiple vulnerabilities in AndSoft's e-TMS

Vulnerability in the cryptographic algorithm of AndSoft's e-TMS v25.03, which uses MD5 to encrypt passwords. MD5 is a cryptographically vulnerable hash algorithm and is no longer considered secure for storing or transmitting passwords. It is vulnerable to collision attacks and can be easily cracked…

πŸ“… Published: Oct. 2, 2025, 2:18 p.m. πŸ”„ Last Modified: Oct. 2, 2025, 7:45 p.m.

8.7

CVSS4.0

CVE-2025-59744 - Multiple vulnerabilities in AndSoft's e-TMS

Path traversal vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to access files only within the web root using the β€œdocurl” parameter in β€œ/lib/asp/DOCSAVEASASP.ASP”.

πŸ“… Published: Oct. 2, 2025, 2:16 p.m. πŸ”„ Last Modified: Oct. 2, 2025, 8:31 p.m.

9.3

CVSS4.0

CVE-2025-59743 - Multiple vulnerabilities in AndSoft's e-TMS

SQL injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability could allow an attacker to retrieve, create, update, and delete databases by sending a POST request. The relationship between parameter and assigned identifier is aΒ 'SessionID' cookie in '/inc/connect/CONNECTION.ASP'.

πŸ“… Published: Oct. 2, 2025, 2:13 p.m. πŸ”„ Last Modified: Oct. 2, 2025, 8:31 p.m.

9.3

CVSS4.0

CVE-2025-59742 - Multiple vulnerabilities in AndSoft's e-TMS

SQL injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability could allow an attacker to retrieve, create, update, and delete databases by sending a POST request. The relationship between parameter and assigned identifier is aΒ 'USRMAIL' parameter in'/inc/login/TRACK_REQUESTFRMSQL.ASP'.

πŸ“… Published: Oct. 2, 2025, 2:11 p.m. πŸ”„ Last Modified: Oct. 2, 2025, 8:30 p.m.

9.3

CVSS4.0

CVE-2025-59741 - Multiple vulnerabilities in AndSoft's e-TMS

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands on the server by sending a POST request. The relationship between parameter and assigned identifier is a 'm' parameter in '/CLT/LOGINERRORFRM.ASP'.

πŸ“… Published: Oct. 2, 2025, 2:08 p.m. πŸ”„ Last Modified: Oct. 2, 2025, 8:29 p.m.

9.3

CVSS4.0

CVE-2025-59740 - Multiple vulnerabilities in AndSoft's e-TMS

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands on the server by sending a POST request. The relationship between parameter and assigned identifier is a 'm' parameter in '/clt/LOGINFRM_CAT.ASP'.

πŸ“… Published: Oct. 2, 2025, 2:07 p.m. πŸ”„ Last Modified: Oct. 2, 2025, 8:29 p.m.

9.3

CVSS4.0

CVE-2025-59739 - Multiple vulnerabilities in AndSoft's e-TMS

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands on the server by sending a POST request. The relationship between parameter and assigned identifier is a 'm' parameter in '/clt/LOGINFRM_original.AS…

πŸ“… Published: Oct. 2, 2025, 2:03 p.m. πŸ”„ Last Modified: Oct. 2, 2025, 8:25 p.m.

9.3

CVSS4.0

CVE-2025-59738 - Multiple vulnerabilities in AndSoft's e-TMS

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands on the server by sending a POST request. The relationship between parameter and assigned identifier is a 'm' parameter in '/clt/LOGINFRM_BET.ASP'.

πŸ“… Published: Oct. 2, 2025, 2:03 p.m. πŸ”„ Last Modified: Oct. 2, 2025, 8:14 p.m.

9.3

CVSS4.0

CVE-2025-59737 - Multiple vulnerabilities in AndSoft's e-TMS

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands on the server by sending a POST request. The relationship between parameter and assigned identifier is a 'm' parameter in '/clt/LOGINFRM_LXA.ASP'.

πŸ“… Published: Oct. 2, 2025, 2:02 p.m. πŸ”„ Last Modified: Oct. 2, 2025, 8:13 p.m.
Total resulsts: 349182
Page 3593 of 34,919
Β« previous page Β» next page
Filters