VendorsArcherydmsarcheryall versions
Vulnerabilities

Archerydms Archery

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2022-38541
Archery v1.8.3 to v1.8.5 was discovered to contain multiple SQL injection vulnerabilities via the start_time and stop_time parameters in the my2sql interface.
Published 2022-09-13 · Modified
9.8EPSS 0.012
CVE-2022-38539
Archery v1.7.5 to v1.8.5 was discovered to contain a SQL injection vulnerability via the where parameter at /archive/apply.
Published 2022-09-13 · Modified
9.8EPSS 0.011
CVE-2022-38542
Archery v1.4.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the ThreadIDs parameter in the kill_session interface. The project has released an update, please upgrade to v1.9.0 and above.
Published 2022-09-13 · Modified
9.8EPSS 0.011
CVE-2022-38538
Archery v1.7.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the checksum parameter in the report module.
Published 2022-09-13 · Modified
9.8EPSS 0.011
CVE-2022-38540
Archery v1.4.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the ThreadIDs parameter in the create_kill_session interface.
Published 2022-09-13 · Modified
9.8EPSS 0.011
CVE-2022-38537
Archery v1.4.5 to v1.8.5 was discovered to contain multiple SQL injection vulnerabilities via the start_file, end_file, start_time, and stop_time parameters in the binlog2sql interface.
Published 2022-09-13 · Modified
9.8EPSS 0.011
CVE-2023-48053
Archery v1.10.0 uses a non-random or static IV for Cipher Block Chaining (CBC) mode in AES encryption. This vulnerability can lead to the disclosure of information and communications.
Published 2023-11-16 · Modified
7.5EPSS 0.004
CVE-2023-30557
SQL injection in data_dictionary.py table_info method in Archery - GHSL-2022-106
Published 2023-04-18 · Modified
6.5EPSS 0.008
CVE-2023-30605
Multiple SQL injections in sql/instance.py param_edit method in Archery - GHSL-2022-104
Published 2023-04-18 · Modified
6.5EPSS 0.008
CVE-2023-30552
SQL injection in sql/instance.py endpoint in Archery - GHSL-2022-101
Published 2023-04-18 · Modified
6.5EPSS 0.008
CVE-2023-30553
Multiple SQL injections in sql_api/api_workflow.py endpoint in Archery - GHSL-2022-102
Published 2023-04-18 · Modified
6.5EPSS 0.008
CVE-2023-30554
SQL injection in sql_api/api_workflow.py endpoint in Archery - GHSL-2022-103
Published 2023-04-18 · Modified
6.5EPSS 0.008
CVE-2023-30555
SQL injection in sql_optimize.py explain method in Archery - GHSL-2022-108
Published 2023-04-18 · Modified
6.5EPSS 0.008
CVE-2023-30556
SQL injection in sql_optimize.py optimize_sqltuningadvisor method in Archery - GHSL-2022-107
Published 2023-04-18 · Modified
6.5EPSS 0.008
CVE-2023-30558
Multiple SQL injections in sql/data_dictionary.py table_list method in Archery - GHSL-2022-105
Published 2023-04-18 · Modified
6.5EPSS 0.008