PT-2011-3472 · Mercator · Mercator Sentinel

Published

2011-09-22

·

Updated

2017-08-17

·

CVE-2011-1913

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Mercator SENTINEL version 2.0
Description A SQL injection issue in the login form of the web interface allows remote attackers to execute arbitrary SQL commands.
Recommendations For Mercator SENTINEL version 2.0, update the software to a version that includes a fix for this issue, if available. As a temporary workaround, consider restricting access to the login form to minimize the risk of exploitation.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-1913

Affected Products

Mercator Sentinel