PT-2019-11586 · Microsoft+1 · Mssql+1

P0W1

·

Publicado

2019-05-31

·

Atualizado

2019-06-03

·

CVE-2019-10123

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Advanced InfoData Systems (AIS) ESEL-Server version 67
Description: The issue allows an anonymous attacker to execute arbitrary code in the context of the user of the MSSQL database. The default user for the database is the sa user.
Recommendations: For Advanced InfoData Systems (AIS) ESEL-Server version 67, consider restricting access to the MSSQL database to minimize the risk of exploitation. As a temporary workaround, limit the privileges of the sa user until a patch is available.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-10123

Produtos afetados

Esel-Server
Mssql