S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Mar 4, 2024

CVE-2021-30175 Scanner

CVE-2021-30175 scanner - SQL Injection vulnerability in ZEROF Web Server

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.4k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-30175
9.8
CVSS

ZEROF Web Server 1.0 (April 2021) allows SQL Injection via the /HandleEvent endpoint for the login page.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

ZEROF Web Server, a lightweight and efficient web server software, is designed to serve web pages and manage web-based applications. The server is often chosen for its simplicity and low resource consumption, making it suitable for small to medium-sized web applications or personal projects. Despite its advantages, like any web server software, it requires diligent security practices to safeguard against potential vulnerabilities.

The vulnerability is triggered when an attacker sends specially crafted data to the /HandleEvent endpoint. This malicious data is improperly sanitized before being used in a SQL query, allowing the attacker to alter the structure of the SQL command and execute arbitrary SQL statements. This could lead to unauthorized access to sensitive information, modification of data, or even full database compromise.

Exploitation of this SQL Injection vulnerability can lead to severe consequences, including unauthorized access to sensitive data, modification or deletion of data, and potential compromise of the server hosting the ZEROF Web Server. The breach could also serve as a foothold for further attacks against the network infrastructure, leading to a broader security compromise.

Joining the S4E platform offers comprehensive vulnerability scanning and cyber threat management. Our platform can detect vulnerabilities like CVE-2021-30175, providing detailed insights and actionable remediation steps. By becoming a member, you gain access to a suite of tools designed to proactively identify and mitigate vulnerabilities, ensuring your digital assets remain secure against emerging threats.

 

References

Solution Advice
  1. Immediately update ZEROF Web Server to the latest version or apply any security patches available from the vendor.
  2. Employ proper input validation techniques to sanitize all user-supplied data before processing it.
  3. Use parameterized queries or prepared statements to prevent SQL Injection attacks.
  4. Regularly review and update security configurations and software to protect against newly discovered vulnerabilities.
  5. Conduct regular security audits and vulnerability assessments to identify and mitigate potential security risks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.