Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p4m7-49xq-h85c

Опубликовано: 08 дек. 2021
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

A SQL injection vulnerability in feature services provided by Esri ArcGIS Server 10.9 and below allows a remote, unauthenticated attacker to impact the confidentiality, integrity and availability of targeted services via specifically crafted queries.

A SQL injection vulnerability in feature services provided by Esri ArcGIS Server 10.9 and below allows a remote, unauthenticated attacker to impact the confidentiality, integrity and availability of targeted services via specifically crafted queries.

EPSS

Процентиль: 62%
0.00427
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.8
nvd
около 4 лет назад

A SQL injection vulnerability in feature services provided by Esri ArcGIS Server 10.9 and below allows a remote, unauthenticated attacker to impact the confidentiality, integrity and availability of targeted services via specifically crafted queries.

CVSS3: 9.8
fstec
больше 4 лет назад

Уязвимость сервера ArcGIS Server, связанная с непринятием мер по защите структуры запроса SQL, позволяющая нарушителю выполнять произвольные SQL-запросы

EPSS

Процентиль: 62%
0.00427
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-89