6.7
CVE-2023-29122 - Incorrect file ownership of privileged service's libraries in Enel X JuiceBox
Under certain conditions, access to service libraries is granted to account they should not have access to.
9.6
CVE-2023-29121 - Exposed TCF agent service in Enel X Juicebox
Waybox Enel TCF Agent service could be used to get administrator’s privileges over the Waybox system.
9.6
CVE-2023-29120 - Unauthorized Remote Command Execution in Enel X Juicebox
Waybox Enel X web management application could be used to execute arbitrary OS commands and provide administrator’s privileges over the Waybox system.
9.6
CVE-2023-29119 - Unauthorized SQLite Injection
Waybox Enel X web management application could execute arbitrary requests on the internal database via /admin/dbstore.php.
9.6
CVE-2023-29118 - Unauthorized SQLite Injection in Enel X Juicebox
Waybox Enel X web management application could execute arbitrary requests on the internal database via /admin/versions.php.
8.8
CVE-2023-29117 - Authentication Bypass in JuiceBox Web Manager interface
Waybox Enel X web management API authentication could be bypassed and provide administrator’s privileges over the Waybox system.
4.3
CVE-2023-29116 - PHP Information Disclosure in Enel X JuiceBox
Under certain conditions, through a request directed to the Waybox Enel X web management application, information like Waybox OS version or service configuration details could be obtained.
6.5
CVE-2023-29115 - Denial of Service via Web Management interface in Enel X JuiceBox
In certain conditions a request directed to the Waybox Enel X Web management application could cause a denial-of-service (e.g. reboot).
5.7
CVE-2023-29114 - Unauthorized System Log Disclosure in Enel X JuiceBox
System logs could be accessed through web management application due to a lack of access control. An attacker can obtain the following sensitive information: •     Wi-Fi access point credentials to which the EV charger can connect. •     APN web address and credentials. •     IPSEC credentials…
6.9
CVE-2024-10845 - 1000 Projects Bookstore Management System book_detail.php sql injection
A vulnerability has been found in 1000 Projects Bookstore Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file book_detail.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been dis…