CVE-2018-12977
Summary
| CVE | CVE-2018-12977 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-07-09 18:29:00 UTC |
| Updated | 2018-09-05 15:41:00 UTC |
| Description | A SQL injection vulnerability in the SoftExpert (SE) Excellence Suite 2.0 allows remote authenticated users to perform SQL heuristics by pulling information from the database with the "cddocument" parameter in the "Downloading Electronic Documents" section. |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Softexpert | Excellence Suite | 2.0 | All | All | All |
| Application | Softexpert | Excellence Suite | 2.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SoftExpert Excellence Suite 2.0 - 'cddocument' SQL Injection - PHP webapps Exploit | EXPLOIT-DB | www.exploit-db.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.