Description
Navarino Infinity web interface up to version 2.2 exposes an unauthenticated script that is prone to blind sql injection. If successfully exploited the user can get info from the underlying postgresql database that could lead into to total compromise of the product. The said script is available with no authentication.
Published: 2018-07-24
Score: 9.8 Critical
EPSS: 3.1% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2018-17155 Navarino Infinity web interface up to version 2.2 exposes an unauthenticated script that is prone to blind sql injection. If successfully exploited the user can get info from the underlying postgresql database that could lead into to total compromise of the product. The said script is available with no authentication.
History

No history.

Subscriptions

Navarino Infinity
cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2024-08-05T05:33:44.385Z

Reserved: 2018-01-12T00:00:00.000Z

Link: CVE-2018-5384

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-07-24T15:29:01.030

Modified: 2024-11-21T04:08:42.813

Link: CVE-2018-5384

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses