Podatność CVE-2022-44015


Publikacja: 2022-12-25

Opis:
An issue was discovered in Simmeth Lieferantenmanager before 5.6. An attacker can inject raw SQL queries. By activating MSSQL features, the attacker is able to execute arbitrary commands on the MSSQL server via the xp_cmdshell extended procedure.

W naszej bazie, znaleźliśmy następujące noty dla tego CVE:
Tytuł
Autor
Data
High
Simmeth System GmbH Supplier Manager LFI / SQL Injection / Bypass
Steffen Robertz
15.11.2022

 Referencje:
https://sec-consult.com/vulnerability-lab/advisory/multiple-critical-vulnerabilities-in-simmeth-system-gmbh-lieferantenmanager/

Copyright 2024, cxsecurity.com

 

Back to Top