漏洞标题
forcedotcom SalesforceMobileSDK-Windows QuerySpec.cs ComputeCountSql SQL注入
漏洞描述信息
**分配时不受支持** 在forcedotcom的SalesforceMobileSDK-Windows 4.x及更早版本中发现了一个漏洞。它已被评为严重。此问题影响文件SalesforceSDK/SmartStore/Store/QuerySpec.cs中的功能ComputeCountSql。该操纵会导致SQL注入。升级到版本5.0.0可以解决此问题。相关的补丁名为83b3e91e0c1e84873a6d3ca3c5887eb5b4f5a3d8。建议升级受影响的组件。此漏洞关联的标识符为VDB-217619。注意:此漏洞仅影响维护者不再支持的产品。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
漏洞类别
N/A
漏洞标题
forcedotcom SalesforceMobileSDK-Windows QuerySpec.cs ComputeCountSql sql injection
漏洞描述信息
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in forcedotcom SalesforceMobileSDK-Windows up to 4.x. It has been rated as critical. This issue affects the function ComputeCountSql of the file SalesforceSDK/SmartStore/Store/QuerySpec.cs. The manipulation leads to sql injection. Upgrading to version 5.0.0 is able to address this issue. The patch is named 83b3e91e0c1e84873a6d3ca3c5887eb5b4f5a3d8. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-217619. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVSS信息
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
漏洞类别
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
漏洞标题
SalesforceMobileSDK-Windows SQL注入漏洞
漏洞描述信息
SalesforceMobileSDK-Windows是Salesforce Platform开源的一个适用于 Salesforce 的 Windows SDK。 SalesforceMobileSDK-Windows 5.0.0之前版本存在SQL注入漏洞,该漏洞源于文件SalesforceSDK/SmartStore/Store/QuerySpec.cs的函数ComputeCountSql存在问题,会导致sql注入。
CVSS信息
N/A
漏洞类别
SQL注入