Moxa SoftCMS CVE-2017-50137 SQL Injection Vulnerability
BID:100557
Info
Moxa SoftCMS CVE-2017-50137 SQL Injection Vulnerability
| Bugtraq ID: | 100557 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-50137 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 31 2017 12:00AM |
| Updated: | Aug 31 2017 12:00AM |
| Credit: | Ziqiang Gu from Huawei WeiRan Labs. |
| Vulnerable: |
Moxa SoftCMS 1.6 Moxa SoftCMS 1.5 Moxa SoftCMS 1.4 Moxa SoftCMS 1.3 Moxa SoftCMS 1.2 |
| Not Vulnerable: |
Moxa SoftCMS 1.7 |
Discussion
Moxa SoftCMS CVE-2017-50137 SQL Injection Vulnerability
Moxa SoftCMS is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied input before using it in an SQL query.
An attacker can exploit this issue to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to Moxa SoftCMS 1.7 are vulnerable.
Moxa SoftCMS is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied input before using it in an SQL query.
An attacker can exploit this issue to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to Moxa SoftCMS 1.7 are vulnerable.
Exploit / POC
Moxa SoftCMS CVE-2017-50137 SQL Injection Vulnerability
An attacker can exploit this issue using a web browser.
An attacker can exploit this issue using a web browser.
Solution / Fix
Moxa SoftCMS CVE-2017-50137 SQL Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Moxa SoftCMS CVE-2017-50137 SQL Injection Vulnerability
References:
References:
- Moxa SoftCMS Home Page (Moxa )
- Advisory (ICSA-17-243-05) Moxa SoftCMS Live Viewer (ICS-CERT)