Skip to content

Update README.md#2

Open
kmcdon83 wants to merge 1 commit intomasterfrom
kmcdon83-patch-2
Open

Update README.md#2
kmcdon83 wants to merge 1 commit intomasterfrom
kmcdon83-patch-2

Conversation

@kmcdon83
Copy link

No description provided.

@kmcdon83
Copy link
Author

Logo
Checkmarx One – Scan Summary & Detailseafa572c-2291-430c-b7c4-c1bd5b2de8b1

New Issues (351)

Checkmarx found the following issues in this Pull Request

Severity Issue Source File / Package Checkmarx Insight
CRITICAL CVE-2010-1870 Maven-org.apache.struts:struts2-core-2.0.11 Vulnerable Package
CRITICAL CVE-2010-1870 Maven-com.opensymphony:xwork-2.0.4 Vulnerable Package
CRITICAL CVE-2012-0391 Maven-com.opensymphony:xwork-2.0.4 Vulnerable Package
CRITICAL CVE-2012-0391 Maven-org.apache.struts:struts2-core-2.0.11 Vulnerable Package
CRITICAL CVE-2012-0392 Maven-org.apache.struts:struts2-core-2.0.11 Vulnerable Package
CRITICAL CVE-2012-0838 Maven-com.opensymphony:xwork-2.0.4 Vulnerable Package
CRITICAL CVE-2012-0838 Maven-org.apache.struts:struts2-core-2.0.11 Vulnerable Package
CRITICAL CVE-2013-1965 Maven-com.opensymphony:xwork-2.0.4 Vulnerable Package
CRITICAL CVE-2013-1965 Maven-org.apache.struts:struts2-core-2.0.11 Vulnerable Package
CRITICAL CVE-2013-2134 Maven-org.apache.struts:struts2-core-2.0.11 Vulnerable Package
CRITICAL CVE-2013-2135 Maven-org.apache.struts:struts2-core-2.0.11 Vulnerable Package
CRITICAL CVE-2013-2251 Maven-org.apache.struts:struts2-core-2.0.11 Vulnerable Package
CRITICAL CVE-2013-4316 Maven-org.apache.struts:struts2-core-2.0.11 Vulnerable Package
CRITICAL CVE-2015-4852 Maven-commons-collections:commons-collections-3.1 Vulnerable Package
CRITICAL CVE-2015-7501 Maven-commons-collections:commons-collections-3.1 Vulnerable Package
CRITICAL CVE-2016-1000027 Maven-org.springframework:spring-web-2.0.5 Vulnerable Package
CRITICAL CVE-2016-1000031 Maven-commons-fileupload:commons-fileupload-1.2.1 Vulnerable Package
CRITICAL CVE-2016-1000031 Maven-commons-fileupload:commons-fileupload-1.1.1 Vulnerable Package
CRITICAL CVE-2016-2170 Maven-commons-collections:commons-collections-3.1 Vulnerable Package
CRITICAL CVE-2016-3082 Maven-org.apache.struts:struts2-core-2.0.11 Vulnerable Package
CRITICAL CVE-2016-4436 Maven-org.apache.struts:struts2-core-2.0.11 Vulnerable Package
CRITICAL CVE-2016-5018 Maven-tomcat:jasper-runtime-5.0.28 Vulnerable Package
CRITICAL CVE-2017-12611 Maven-org.apache.struts:struts2-core-2.0.11 Vulnerable Package
CRITICAL CVE-2017-5638 Maven-org.apache.struts:struts2-core-2.0.11 Vulnerable Package
CRITICAL CVE-2019-0230 Maven-org.apache.struts:struts2-core-2.0.11 Vulnerable Package
CRITICAL CVE-2019-17571 Maven-log4j:log4j-1.2.9 Vulnerable Package
CRITICAL CVE-2020-10683 Maven-dom4j:dom4j-1.4 Vulnerable Package
CRITICAL CVE-2020-17530 Maven-org.apache.struts:struts2-core-2.0.11 Vulnerable Package
CRITICAL CVE-2022-22965 Maven-org.springframework:spring-beans-2.0.5 Vulnerable Package
CRITICAL CVE-2022-23305 Maven-log4j:log4j-1.2.9 Vulnerable Package
CRITICAL CVE-2022-41853 Maven-org.hsqldb:hsqldb-2.3.2 Vulnerable Package
CRITICAL CVE-2023-50164 Maven-org.apache.struts:struts2-core-2.0.11 Vulnerable Package
CRITICAL CVE-2024-53677 Maven-org.apache.struts:struts2-core-2.0.11 Vulnerable Package
CRITICAL Command_Injection /riches.java/riches/pages/common/hidden_AdminControl.jsp: 74
detailsThe application's hidden_AdminControl method calls an OS (shell) command with exec, at line 95 of /riches.java/riches/pages/common/hidden_AdminCont...
Attack Vector
CRITICAL Command_Injection /riches.java/riches/WEB-INF/src/java/com/fortify/samples/riches/oper/SendMessage.java: 60
detailsThe application's sendMail method calls an OS (shell) command with exec, at line 83 of /riches.java/riches/WEB-INF/src/java/com/fortify/samples/ric...
Attack Vector
CRITICAL Command_Injection /riches.java/riches/WEB-INF/src/java/com/fortify/samples/riches/oper/SendMessage.java: 60
detailsThe application's sendMail method calls an OS (shell) command with exec, at line 83 of /riches.java/riches/WEB-INF/src/java/com/fortify/samples/ric...
Attack Vector
CRITICAL Command_Injection /riches.java/riches/WEB-INF/src/java/com/fortify/samples/riches/oper/SendMessage.java: 60
detailsThe application's sendMail method calls an OS (shell) command with exec, at line 83 of /riches.java/riches/WEB-INF/src/java/com/fortify/samples/ric...
Attack Vector
CRITICAL Command_Injection /riches.java/riches/WEB-INF/src/java/com/fortify/samples/riches/oper/SendMessage.java: 60
detailsThe application's sendMail method calls an OS (shell) command with exec, at line 83 of /riches.java/riches/WEB-INF/src/java/com/fortify/samples/ric...
Attack Vector
CRITICAL Command_Injection /riches.java/riches/WEB-INF/src/java/com/fortify/samples/riches/oper/SendMessage.java: 52
detailsThe application's sendMail method calls an OS (shell) command with exec, at line 83 of /riches.java/riches/WEB-INF/src/java/com/fortify/samples/ric...
Attack Vector
CRITICAL Command_Injection /riches.java/riches/WEB-INF/src/java/com/fortify/samples/riches/oper/SendMessage.java: 52
detailsThe application's sendMail method calls an OS (shell) command with exec, at line 83 of /riches.java/riches/WEB-INF/src/java/com/fortify/samples/ric...
Attack Vector
CRITICAL Command_Injection /riches.java/riches/WEB-INF/src/java/com/fortify/samples/riches/oper/SendMessage.java: 52
detailsThe application's sendMail method calls an OS (shell) command with exec, at line 83 of /riches.java/riches/WEB-INF/src/java/com/fortify/samples/ric...
Attack Vector
CRITICAL Command_Injection /riches.java/riches/WEB-INF/src/java/com/fortify/samples/riches/oper/SendMessage.java: 52
detailsThe application's sendMail method calls an OS (shell) command with exec, at line 83 of /riches.java/riches/WEB-INF/src/java/com/fortify/samples/ric...
Attack Vector
CRITICAL Command_Injection /riches.java/riches/WEB-INF/src/java/com/fortify/samples/riches/oper/SendNewsletter.java: 47
detailsThe application's sendMail method calls an OS (shell) command with exec, at line 61 of /riches.java/riches/WEB-INF/src/java/com/fortify/samples/ric...
Attack Vector
CRITICAL Command_Injection /riches.java/riches/WEB-INF/src/java/com/fortify/samples/riches/oper/SendNewsletter.java: 47
detailsThe application's sendMail method calls an OS (shell) command with exec, at line 61 of /riches.java/riches/WEB-INF/src/java/com/fortify/samples/ric...
Attack Vector
CRITICAL Command_Injection /riches.java/riches/WEB-INF/src/java/com/fortify/samples/riches/oper/SendNewsletter.java: 39
detailsThe application's sendMail method calls an OS (shell) command with exec, at line 61 of /riches.java/riches/WEB-INF/src/java/com/fortify/samples/ric...
Attack Vector
CRITICAL Command_Injection /riches.java/riches/WEB-INF/src/java/com/fortify/samples/riches/oper/SendNewsletter.java: 39
detailsThe application's sendMail method calls an OS (shell) command with exec, at line 61 of /riches.java/riches/WEB-INF/src/java/com/fortify/samples/ric...
Attack Vector
CRITICAL SQL_Injection /riches.net/RichesDotnet/App_Code/Restful/RestfulServices.cs: 65
detailsThe application's GetTransactionData method executes an SQL query with Fill, at line 85 of /riches.net/RichesDotnet/App_Code/Components/Transaction...
Attack Vector
CRITICAL SQL_Injection /riches.net/RichesDotnet/App_Code/Restful/RestfulServices.cs: 57
detailsThe application's GetTransactionData method executes an SQL query with Fill, at line 85 of /riches.net/RichesDotnet/App_Code/Components/Transaction...
Attack Vector
CRITICAL SQL_Injection /riches.net/RichesDotnet/Users/AdminControlPage.aspx.cs: 96
detailsThe application's GetTransactionData method executes an SQL query with Fill, at line 85 of /riches.net/RichesDotnet/App_Code/Components/Transaction...
Attack Vector
CRITICAL SQL_Injection /riches.net/RichesDotnet/App_Code/Restful/RestfulServices.cs: 74
detailsThe application's GetTransactionData method executes an SQL query with Fill, at line 85 of /riches.net/RichesDotnet/App_Code/Components/Transaction...
Attack Vector
CRITICAL SQL_Injection /riches.net/RichesDotnet/App_Code/Restful/RestfulServices.cs: 74
detailsThe application's GetTransactionData method executes an SQL query with Fill, at line 85 of /riches.net/RichesDotnet/App_Code/Components/Transaction...
Attack Vector
CRITICAL SQL_Injection /riches.net/RichesDotnet/Users/AccountDetails.aspx.cs: 25
detailsThe application's GetTransactionData method executes an SQL query with Fill, at line 85 of /riches.net/RichesDotnet/App_Code/Components/Transaction...
Attack Vector
CRITICAL SQL_Injection /riches.net/RichesDotnet/App_Code/Restful/RestfulServices.cs: 74
detailsThe application's GetTransactionData method executes an SQL query with Fill, at line 85 of /riches.net/RichesDotnet/App_Code/Components/Transaction...
Attack Vector
CRITICAL SQL_Injection /riches.net/RichesDotnet/App_Code/Restful/RestfulServices.cs: 48
detailsThe application's GetAccountDataForUser method executes an SQL query with Fill, at line 41 of /riches.net/RichesDotnet/App_Code/Components/AccountD...
Attack Vector
CRITICAL SQL_Injection /riches.net/RichesDotnet/App_Code/Restful/RestfulServices.cs: 40
detailsThe application's GetAccountDataForUser method executes an SQL query with Fill, at line 41 of /riches.net/RichesDotnet/App_Code/Components/AccountD...
Attack Vector
CRITICAL SQL_Injection /riches.net/RichesDotnet/Anonymous/FindLocations.aspx.cs: 58
detailsThe application's FindAtmLocationByAddress method executes an SQL query with Fill, at line 43 of /riches.net/RichesDotnet/App_Code/Components/Locat...
Attack Vector
CRITICAL SQL_Injection /riches.net/RichesDotnet/Anonymous/FindLocations.aspx.cs: 58
detailsThe application's FindAtmLocationByAddress method executes an SQL query with Fill, at line 43 of /riches.net/RichesDotnet/App_Code/Components/Locat...
Attack Vector
CRITICAL SQL_Injection /riches.net/RichesDotnet/Anonymous/FindLocations.aspx.cs: 58
detailsThe application's FindAtmLocationByAddress method executes an SQL query with Fill, at line 43 of /riches.net/RichesDotnet/App_Code/Components/Locat...
Attack Vector
CRITICAL SQL_Injection /riches.net/RichesDotnet/App_Code/Restful/RestfulServices.cs: 164
detailsThe application's updateBalance method executes an SQL query with ExecuteNonQuery, at line 109 of /riches.net/RichesDotnet/App_Code/Components/Acco...
Attack Vector
CRITICAL SQL_Injection /riches.net/RichesDotnet/App_Code/Restful/RestfulServices.cs: 141
detailsThe application's updateBalance method executes an SQL query with ExecuteNonQuery, at line 109 of /riches.net/RichesDotnet/App_Code/Components/Acco...
Attack Vector
CRITICAL SQL_Injection /riches.net/RichesDotnet/App_Code/Restful/RestfulServices.cs: 118
detailsThe application's updateBalance method executes an SQL query with ExecuteNonQuery, at line 109 of /riches.net/RichesDotnet/App_Code/Components/Acco...
Attack Vector
CRITICAL SQL_Injection /riches.net/RichesDotnet/Users/Transfer.aspx.cs: 30
detailsThe application's updateBalance method executes an SQL query with ExecuteNonQuery, at line 109 of /riches.net/RichesDotnet/App_Code/Components/Acco...
Attack Vector
CRITICAL SQL_Injection /riches.net/RichesDotnet/Users/Transfer.aspx.cs: 29
detailsThe application's updateBalance method executes an SQL query with ExecuteNonQuery, at line 109 of /riches.net/RichesDotnet/App_Code/Components/Acco...
Attack Vector
CRITICAL SQL_Injection /riches.net/RichesDotnet/Anonymous/FindLocations.aspx.cs: 49
detailsThe application's FindAtmByZip method executes an SQL query with Fill, at line 31 of /riches.net/RichesDotnet/App_Code/Components/LocationDB.cs. Th...
Attack Vector
CRITICAL SQL_Injection /riches.net/RichesDotnet/Anonymous/FindLocations.aspx.cs: 20
detailsThe application's FindAtmByZip method executes an SQL query with Fill, at line 31 of /riches.net/RichesDotnet/App_Code/Components/LocationDB.cs. Th...
Attack Vector
CRITICAL SQL_Injection /riches.net/RichesDotnet/App_Code/Restful/RestfulServices.cs: 164
detailsThe application's getBalance method executes an SQL query with ExecuteReader, at line 87 of /riches.net/RichesDotnet/App_Code/Components/AccountDB....
Attack Vector
CRITICAL SQL_Injection /riches.net/RichesDotnet/App_Code/Restful/RestfulServices.cs: 141
detailsThe application's getBalance method executes an SQL query with ExecuteReader, at line 87 of /riches.net/RichesDotnet/App_Code/Components/AccountDB....
Attack Vector
CRITICAL SQL_Injection /riches.net/RichesDotnet/App_Code/Restful/RestfulServices.cs: 118
detailsThe application's getBalance method executes an SQL query with ExecuteReader, at line 87 of /riches.net/RichesDotnet/App_Code/Components/AccountDB....
Attack Vector
CRITICAL SQL_Injection /riches.net/RichesDotnet/Users/Transfer.aspx.cs: 30
detailsThe application's getBalance method executes an SQL query with ExecuteReader, at line 87 of /riches.net/RichesDotnet/App_Code/Components/AccountDB....
Attack Vector
CRITICAL SQL_Injection /riches.net/RichesDotnet/Users/Transfer.aspx.cs: 29
detailsThe application's getBalance method executes an SQL query with ExecuteReader, at line 87 of /riches.net/RichesDotnet/App_Code/Components/AccountDB....
Attack Vector
CRITICAL SQL_Injection /riches.java/riches/WEB-INF/src/java/com/fortify/samples/riches/AccountDetails.java: 58
detailsThe application's getTransactionsDebug method executes an SQL query with list, at line 63 of /riches.java/riches/WEB-INF/src/java/com/fortify/sampl...
Attack Vector
CRITICAL SQL_Injection /riches.java/riches/WEB-INF/src/java/com/fortify/samples/riches/AccountDetails.java: 58
detailsThe application's getTransactions method executes an SQL query with list, at line 44 of /riches.java/riches/WEB-INF/src/java/com/fortify/samples/ri...
Attack Vector
CRITICAL SQL_Injection /riches.java/riches/WEB-INF/src/java/com/fortify/samples/riches/FindLocations.java: 50
detailsThe application's findByZip method executes an SQL query with executeQuery, at line 111 of /riches.java/riches/WEB-INF/src/java/com/fortify/samples...
Attack Vector
CRITICAL SQL_Injection /riches.java/riches/WEB-INF/src/java/com/fortify/samples/riches/FindLocations.java: 28
detailsThe application's findAtmByZip method executes an SQL query with list, at line 70 of /riches.java/riches/WEB-INF/src/java/com/fortify/samples/riche...
Attack Vector
CRITICAL SQL_Injection /riches.java/riches/WEB-INF/src/java/com/fortify/samples/riches/Messages.java: 20
detailsThe application's getMessage method executes an SQL query with list, at line 138 of /riches.java/riches/WEB-INF/src/java/com/fortify/samples/riches...
Attack Vector
CRITICAL SQL_Injection /riches.java/riches/WEB-INF/src/java/com/fortify/samples/riches/FindLocations.java: 32
detailsThe application's findAtmByAddress method executes an SQL query with executeQuery, at line 139 of /riches.java/riches/WEB-INF/src/java/com/fortify/...
Attack Vector
CRITICAL SQL_Injection /riches.java/riches/WEB-INF/src/java/com/fortify/samples/riches/FindLocations.java: 32
detailsThe application's findAtmByAddress method executes an SQL query with executeQuery, at line 139 of /riches.java/riches/WEB-INF/src/java/com/fortify/...
Attack Vector
CRITICAL SQL_Injection /riches.java/riches/WEB-INF/src/java/com/fortify/samples/riches/FindLocations.java: 32
detailsThe application's findAtmByAddress method executes an SQL query with executeQuery, at line 139 of /riches.java/riches/WEB-INF/src/java/com/fortify/...
Attack Vector
CRITICAL Second_Order_SQL_Injection /riches.net/RichesDotnet/App_Code/Components/AccountDB.cs: 66
detailsThe application's updateBalance method executes an SQL query with ExecuteNonQuery, at line 109 of /riches.net/RichesDotnet/App_Code/Components/Acco...
Attack Vector
CRITICAL Second_Order_SQL_Injection /riches.net/RichesDotnet/App_Code/Components/AccountDB.cs: 66
detailsThe application's getCcn method executes an SQL query with ExecuteReader, at line 119 of /riches.net/RichesDotnet/App_Code/Components/AccountDB.cs....
Attack Vector
CRITICAL Second_Order_SQL_Injection /riches.net/RichesDotnet/App_Code/Components/AccountDB.cs: 66
detailsThe application's getBalance method executes an SQL query with ExecuteReader, at line 87 of /riches.net/RichesDotnet/App_Code/Components/AccountDB....
Attack Vector
CRITICAL Stored_XSS /riches.net/RichesDotnet/App_Code/Components/ProfileDB.cs: 46
detailsThe method Page_Load embeds untrusted data in generated output with Text, at line 14 of /riches.net/RichesDotnet/Users/UsersMaster.master.cs. This ...
Attack Vector
CRITICAL Stored_XSS /riches.net/RichesDotnet/App_Code/Components/ProfileDB.cs: 46
detailsThe method Page_Load embeds untrusted data in generated output with Text, at line 14 of /riches.net/RichesDotnet/Admin/AdminMaster.master.cs. This ...
Attack Vector
CRITICAL Stored_XSS /riches.net/RichesDotnet/Users/ViewMessage.aspx: 30
detailsThe method Checkmarx_Container embeds untrusted data in generated output with Write, at line 1 of /riches.net/RichesDotnet/Users/ViewMessage.aspx. ...
Attack Vector
CRITICAL Stored_XSS /riches.java/riches/WEB-INF/src/java/com/fortify/samples/riches/model/TransactionService.java: 168
detailsThe method GetTransactions embeds untrusted data in generated output with GetTransactionsXML, at line 118 of /riches.java/riches/WEB-INF/src/java/c...
Attack Vector
CRITICAL Stored_XSS /riches.java/riches/pages/FilesViewer.jsp: 13
detailsThe method FilesViewer embeds untrusted data in generated output with println, at line 15 of /riches.java/riches/pages/FilesViewer.jsp. This untrus...
Attack Vector
CRITICAL Stored_XSS /riches.java/riches/pages/Backup.jsp: 11
detailsThe method Backup embeds untrusted data in generated output with print, at line 12 of /riches.java/riches/pages/Backup.jsp. This untrusted data is ...
Attack Vector
HIGH CVE-2006-1546 Maven-struts:struts-1.1 Vulnerable Package
HIGH CVE-2006-1547 Maven-struts:struts-1.1 Vulnerable Package
HIGH CVE-2011-2730 Maven-org.springframework:spring-web-2.0.5 Vulnerable Package
HIGH CVE-2012-1592 Maven-org.apache.struts:struts2-core-2.0.11 Vulnerable Package
HIGH CVE-2013-2186 Maven-commons-fileupload:commons-fileupload-1.2.1 Vulnerable Package
HIGH CVE-2013-2186 Maven-commons-fileupload:commons-fileupload-1.1.1 Vulnerable Package

More results are available on the CxOne platform

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant