Description
RockOA 1.8.7 allows remote attackers to obtain sensitive information because the webmain/webmainAction.php publictreestore method constructs a SQL WHERE clause unsafely by using the pidfields and idfields parameters, aka background SQL injection.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-19202 | RockOA 1.8.7 allows remote attackers to obtain sensitive information because the webmain/webmainAction.php publictreestore method constructs a SQL WHERE clause unsafely by using the pidfields and idfields parameters, aka background SQL injection. |
References
| Link | Providers |
|---|---|
| https://www.seebug.org/vuldb/ssvid-97861 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T22:01:55.105Z
Reserved: 2019-03-16T00:00:00.000Z
Link: CVE-2019-9846
No data.
Status : Modified
Published: 2019-06-28T16:15:09.573
Modified: 2024-11-21T04:52:25.667
Link: CVE-2019-9846
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD