Emuse - eServices / eNvoice SQL injection can be used in various ways ranging from bypassing login authentication or dumping the whole database to full RCE on the affected endpoints. The SQLi caused by CWE-209: Generation of Error Message Containig Sensetive Information, showing parts of the aspx code and the webroot location , information an attacker can leverage to further compromise the host.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.gov.il/en/departments/faq/cve_advisories |
History
Mon, 16 Sep 2024 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | Emuse - eServices / eNvoice SQL injection | Emuse - eServices / eNvoice SQL injection |
MITRE
Status: PUBLISHED
Assigner: INCD
Published: 2021-12-29T14:13:38.766729Z
Updated: 2024-09-16T18:38:48.510Z
Reserved: 2021-07-12T00:00:00
Link: CVE-2021-36722
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2021-12-29T15:15:07.757
Modified: 2022-01-11T14:12:33.257
Link: CVE-2021-36722
Redhat
No data.