Description
Huawei UMA V200R001C00 has a SQL injection vulnerability in the operation and maintenance module. An attacker logs in to the system as a common user and sends crafted HTTP requests that contain malicious SQL statements to the affected system. Due to a lack of input validation on HTTP requests that contain user-supplied input, successful exploitation may allow the attacker to execute arbitrary SQL queries.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-6785 | Huawei UMA V200R001C00 has a SQL injection vulnerability in the operation and maintenance module. An attacker logs in to the system as a common user and sends crafted HTTP requests that contain malicious SQL statements to the affected system. Due to a lack of input validation on HTTP requests that contain user-supplied input, successful exploitation may allow the attacker to execute arbitrary SQL queries. |
References
History
No history.
Status: PUBLISHED
Assigner: huawei
Published:
Updated: 2024-08-05T19:50:16.490Z
Reserved: 2017-10-14T00:00:00.000Z
Link: CVE-2017-15329
No data.
Status : Modified
Published: 2018-02-15T16:29:00.203
Modified: 2024-11-21T03:14:28.520
Link: CVE-2017-15329
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD