VendorsKironadynamic_resource_scheduling5.5.3.5
Vulnerabilities

Kirona Dynamic Resource Scheduling 5.5.3.5

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2019-17504
An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. A reflected Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script via the /osm/report/ password parameter.
Published 2019-10-11 · Modified
6.11 PoCEPSS 0.028
CVE-2019-17503
An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. An unauthenticated user can access /osm/REGISTER.cmd (aka /osm_tiles/REGISTER.cmd) directly: it contains sensitive information about the database through the SQL queries within this batch file. This file exposes SQL database information such as database version, table name, column name, etc.
Published 2019-10-11 · Modified
5.31 PoCEPSS 0.483