Skip to content

Instantly share code, notes, and snippets.

[CVE ID]
CVE-2024-39209
[PRODUCT]
luci-app-sms-tool
[VERSION]
<= 1.9-6
[PROBLEM TYPE]
command injection
[DESCRIPTION]
luci-app-sms-tool v1.9-6 was discovered to contain a command injection vulnerability via the score parameter.
[CVE ID]
CVE-2024-39208
[PRODUCT]
luci-app-lucky
[VERSION]
<= 2.8.3
[PROBLEM TYPE]
Unauthorized access
[DESCRIPTION]
luci-app-lucky v2.8.3 was discovered to contain hardcoded credentials.
[CVE ID]
CVE-2024-39207
[PRODUCT]
lua-shmem
[VERSION]
<= 1.0-1
[PROBLEM TYPE]
buffer overflow
[DESCRIPTION]
lua-shmem v1.0-1 was discovered to contain a buffer overflow via the shmem_write function.