漏洞标题
ESAFENET CDG MultiServerAjax软件存在注入漏洞
漏洞描述信息
在ESAFENET CDG 5中发现了一个漏洞,并被归类为严重漏洞。该漏洞影响文件/com/esafenet/servlet/ajax/MultiServerAjax.java中的connectLogout函数。通过操纵参数servername可导致SQL注入。攻击者可能远程利用此漏洞。该漏洞的利用方法已经公开,可能被利用。已提前联系了厂商,但厂商没有做出任何回应。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
漏洞类别
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
漏洞标题
ESAFENET CDG MultiServerAjax.java connectLogout sql injection
漏洞描述信息
A vulnerability was found in ESAFENET CDG 5 and classified as critical. Affected by this issue is the function connectLogout of the file /com/esafenet/servlet/ajax/MultiServerAjax.java. The manipulation of the argument servername leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
漏洞类别
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
漏洞标题
EsafeNet CDG SQL注入漏洞
漏洞描述信息
EsafeNet CDG是中国亿赛通(EsafeNet)公司的一套文档安全管理系统。 EsafeNet CDG存在SQL注入漏洞,该漏洞源于对参数servername的错误操作会导致sql注入。
CVSS信息
N/A
漏洞类别
SQL注入