Vulnerabilities
Vulnerable Software
Slican:  Security Vulnerabilities
Slican NCP/IPL/IPM/IPU devices are vulnerable to PHP Function Injection. An unauthenticated remote attacker is able to execute arbitrary PHP commands by sending specially crafted requests to /webcti/session_ajax.php endpoint. This issue was fixed in version 1.24.0190 (Slican NCP) and 6.61.0010 (Slican IPL/IPM/IPU).
CVSS Score
9.3
EPSS Score
0.001
Published
2026-02-24
SLICAN WebCTI 1.01 2015 is affected by a Cross Site Scripting (XSS) vulnerability. The attacker can steal the user's session by injecting malicious JavaScript codes which leads to Session Hijacking and cause user's credentials theft.
CVSS Score
6.1
EPSS Score
0.002
Published
2021-12-28


Contact Us

Shodan ® - All rights reserved