Логотип exploitDog
bind:CVE-2024-51962
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-51962

Количество 3

Количество 3

nvd логотип

CVE-2024-51962

11 месяцев назад

A SQL injection vulnerability in ArcGIS Server allows an EDIT operation to modify column properties in a manner that could lead to SQL injection when performed by a remote authenticated user requiring elevated, non‑administrative privileges. Exploitation is restricted to users with advanced application‑specific permissions, indicating high privileges are required. Successful exploitation would have a high impact on integrity and confidentiality, with no impact on availability.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-g274-9873-jcxx

11 месяцев назад

A SQL injection vulnerability in ArcGIS Server allows an EDIT operation to modify Column properties allowing for the execution of a SQL Injection by a remote authenticated user with elevated (non admin) privileges.  There is a high impact to integrity and confidentiality and no impact to availability.

CVSS3: 8.7
EPSS: Низкий
fstec логотип

BDU:2025-02367

12 месяцев назад

Уязвимость сервера ArcGIS Server, связанная с непринятием мер по защите структуры запроса SQL, позволяющая нарушителю повысить свои привилегии и выполнить произвольный код

CVSS3: 8.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-51962

A SQL injection vulnerability in ArcGIS Server allows an EDIT operation to modify column properties in a manner that could lead to SQL injection when performed by a remote authenticated user requiring elevated, non‑administrative privileges. Exploitation is restricted to users with advanced application‑specific permissions, indicating high privileges are required. Successful exploitation would have a high impact on integrity and confidentiality, with no impact on availability.

CVSS3: 8.7
0%
Низкий
11 месяцев назад
github логотип
GHSA-g274-9873-jcxx

A SQL injection vulnerability in ArcGIS Server allows an EDIT operation to modify Column properties allowing for the execution of a SQL Injection by a remote authenticated user with elevated (non admin) privileges.  There is a high impact to integrity and confidentiality and no impact to availability.

CVSS3: 8.7
0%
Низкий
11 месяцев назад
fstec логотип
BDU:2025-02367

Уязвимость сервера ArcGIS Server, связанная с непринятием мер по защите структуры запроса SQL, позволяющая нарушителю повысить свои привилегии и выполнить произвольный код

CVSS3: 8.7
0%
Низкий
12 месяцев назад

Уязвимостей на страницу