漏洞标题
N/A
漏洞描述信息
**争议** WebDB 1.1 早期版本中允许远程攻击者通过未指定 search 参数执行任意 SQL 命令的漏洞,可能允许攻击者通过 Search0 等参数执行。Note:供应商对此表示否认,称“WebDB 是 Lois Software 许多客户的通用在线数据库系统。 identified 的漏洞是为客户对其系统进行测试而添加的一些代码,仅允许某些安全命令。现已删除此代码,现在无法在查询字符串中使用 SQL 查询。无需安装或更新,所有客户端使用共同代码库,并具有自己的前端和数据库以及连接。因此,一旦代码进行更改/升级/增强,软件的所有用户都将立即开始使用最新更改。”由于问题出现在自定义网站,且客户无需采取行动,因此这个问题不应包含在 CVE(通用漏洞披露)中。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
漏洞类别
N/A
漏洞标题
N/A
漏洞描述信息
SQL injection vulnerability in WebDB 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified search parameters, possibly Search0. NOTE: the vendor has disputed this issue, saying that "WebDB is a generic online database system used by many of the clients of Lois Software. The flaw that was identified was some code that was added for a client to do some testing of his system and only certain safe commands were allowed. This code has now been removed and it is not now possible to use SQL queries as part of the query string. No installation or patch is required All clients use a common code library and have their own front end and databases and connections. So as soon as a change / upgrade / enhancement is made to the code, all users of the software begin to use the latest changes immediately." Since the issue appeared in a custom web site and no action is required on the part of customers, this issue should not be included in CVE
CVSS信息
N/A
漏洞类别
N/A
漏洞标题
Lois Software WebDB搜索模块SQL注入漏洞
漏洞描述信息
** 争议 ** WebDB 1.1及更早版本存在SQL注入漏洞,远程攻击者可以通过未明搜索参数,可能是Search0,来执行任意SQL命令。
CVSS信息
N/A
漏洞类别
SQL注入