漏洞标题
N/A
漏洞描述信息
请求缓存图像可能会滥用,包括未经检查的SQL查询。利用此漏洞需要至少访问图像转换服务相邻的网络,该服务默认不会向公共网络暴露。可以在服务数据库用户账户上下文执行任意的SQL语句。现在正正确检查API请求中的有效内容,试图绕过此检查将被视为错误。目前已知的漏洞公开利用不存在。
CVSS信息
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
漏洞类别
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
漏洞标题
N/A
漏洞描述信息
Requests to cache an image could be abused to include SQL queries that would be executed unchecked. Exploiting this vulnerability requires at least access to adjacent networks of the imageconverter service, which is not exposed to public networks by default. Arbitrary SQL statements could be executed in the context of the services database user account. API requests are now properly checked for valid content and attempts to circumvent this check are being logged as error. No publicly available exploits are known.
CVSS信息
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
漏洞类别
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
漏洞标题
Open-Xchange App Suite SQL注入漏洞
漏洞描述信息
Open-Xchange App Suite是德国Open-Xchange公司的一个电子邮件及生产力套件客户端软件。 Open-Xchange App Suite 存在安全漏洞,该漏洞源于存在一个 SQL 注入漏洞。
CVSS信息
N/A
漏洞类别
SQL注入