Описание
OpenBMCS 2.4 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting arbitrary SQL code. Attackers can send GET requests to /debug/obix_test.php with malicious 'id' values to extract database information.
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- Product
- Third Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:openbmcs:openbmcs:2.4:*:*:*:*:*:*:*
EPSS
Процентиль: 21%
0.00068
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-89
Связанные уязвимости
CVSS3: 6.5
github
2 месяца назад
OpenBMCS 2.4 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting arbitrary SQL code. Attackers can send GET requests to /debug/obix_test.php with malicious 'id' values to extract database information.
EPSS
Процентиль: 21%
0.00068
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-89