Skip to main content

Vendor archive

globalnorthstar CVEs

Beta · best-effort

7 CVEs tagged to vendor globalnorthstar3 Critical, 2 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2022-26959

Published Sep 16, 2022

There are two full (read/write) Blind/Time-based SQL injection vulnerabilities in the Northstar Club Management version 6.3 application. The vulnerabilities exist in the userName…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-29398

Published Feb 4, 2022

Directory traversal in /northstar/Common/NorthFileManager/fileManagerObjects.jsp Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to br…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-29397

Published Feb 4, 2022

Cleartext Transmission of Sensitive Information in /northstar/Admin/login.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote local user to intercept use…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-29396

Published Feb 4, 2022

Systemic Insecure Permissions in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to use various functionalities without authentication.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-29395

Published Feb 4, 2022

Directory travesal in /northstar/filemanager/download.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to download arbitrary fil…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-29394

Published Feb 4, 2022

Account Hijacking in /northstar/Admin/changePassword.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote authenticated users to change the password of an…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-29393

Published Feb 4, 2022

Remote Code Execution in cominput.jsp and comoutput.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to inject and execute arbit…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1