CVE-2018-12464
Summary
| CVE | CVE-2018-12464 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-06-29 16:29:00 UTC |
| Updated | 2023-11-07 02:52:00 UTC |
| Description | A SQL injection vulnerability in the web administration and quarantine components of Micro Focus Secure Messaging Gateway allows an unauthenticated remote attacker to execute arbitrary SQL statements against the database. This can be exploited to create an administrative account and used in conjunction with CVE-2018-12465 to achieve unauthenticated remote code execution. Affects Micro Focus Secure Messaging Gateway versions prior to 471. It does not affect previous versions of the product that use the GWAVA product name (i.e. GWAVA 6.5). |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microfocus | Secure Messaging Gateway | All | All | All | All |
| Application | Microfocus | Secure Messaging Gateway | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| support.microfocus.com/kb/doc.php | CONFIRM | support.microfocus.com | Vendor Advisory |
| Unexpected Journey #6 – All ways lead to Rome ! Remote Code Execution on MicroFocus Secure Messaging Gateway – Pentest Blog | CONFIRM | pentest.blog | Exploit, Third Party Advisory |
| Micro Focus Secure Messaging Gateway (SMG) < 471 - Remote Code Execution (Metasploit) - PHP webapps Exploit | www.exploit-db.com | ||
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Mehmet INCE from PRODAFT
There are currently no legacy QID mappings associated with this CVE.