Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w8xx-5j5x-h7v6

Опубликовано: 09 дек. 2021
Источник: github
Github: Не прошло ревью

Описание

A SQL Injection in the custom filter query component in Genesys intelligent Workload Distribution (IWD) 9.0.017.07 allows an attacker to execute arbitrary SQL queries via the value attribute, with which all data in the database can be extracted and OS command execution is possible depending on the permissions and/or database engine.

A SQL Injection in the custom filter query component in Genesys intelligent Workload Distribution (IWD) 9.0.017.07 allows an attacker to execute arbitrary SQL queries via the value attribute, with which all data in the database can be extracted and OS command execution is possible depending on the permissions and/or database engine.

EPSS

Процентиль: 84%
0.02164
Низкий

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 7.2
nvd
около 4 лет назад

A SQL Injection in the custom filter query component in Genesys intelligent Workload Distribution (IWD) 9.0.017.07 allows an attacker to execute arbitrary SQL queries via the value attribute, with which all data in the database can be extracted and OS command execution is possible depending on the permissions and/or database engine.

EPSS

Процентиль: 84%
0.02164
Низкий

Дефекты

CWE-89