Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7wvg-v832-h9xq

Опубликовано: 30 дек. 2021
Источник: github
Github: Не прошло ревью

Описание

Emuse - eServices / eNvoice SQL injection can be used in various ways ranging from bypassing login authentication or dumping the whole database to full RCE on the affected endpoints. The SQLi caused by CWE-209: Generation of Error Message Containig Sensetive Information, showing parts of the aspx code and the webroot location , information an attacker can leverage to further compromise the host.

Emuse - eServices / eNvoice SQL injection can be used in various ways ranging from bypassing login authentication or dumping the whole database to full RCE on the affected endpoints. The SQLi caused by CWE-209: Generation of Error Message Containig Sensetive Information, showing parts of the aspx code and the webroot location , information an attacker can leverage to further compromise the host.

EPSS

Процентиль: 41%
0.00192
Низкий

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 7.1
nvd
около 4 лет назад

Emuse - eServices / eNvoice SQL injection can be used in various ways ranging from bypassing login authentication or dumping the whole database to full RCE on the affected endpoints. The SQLi caused by CWE-209: Generation of Error Message Containig Sensetive Information, showing parts of the aspx code and the webroot location , information an attacker can leverage to further compromise the host.

EPSS

Процентиль: 41%
0.00192
Низкий

Дефекты

CWE-89