UltraLog Express device management interface does not properly filter user inputted string in some specific parameters, attackers can inject arbitrary SQL command.
Subscriptions
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-25201 | UltraLog Express device management interface does not properly filter user inputted string in some specific parameters, attackers can inject arbitrary SQL command. |
Fixes
Solution
Update to V1.5.0 or later version.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-3451-7d9f0-1.html |
|
History
Tue, 24 Feb 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 16 Sep 2024 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | UltraLog Express device management interface does not properly filter user inputted string in some specific parameters, attackers can inject arbitrary SQL command. | UltraLog Express device management interface does not properly filter user inputted string in some specific parameters, attackers can inject arbitrary SQL command. |
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-16T22:51:08.505Z
Reserved: 2019-12-20T00:00:00.000Z
Link: CVE-2020-3936
Updated: 2024-08-04T07:52:20.524Z
Status : Modified
Published: 2020-03-27T04:15:10.913
Modified: 2024-11-21T05:31:59.690
Link: CVE-2020-3936
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD