SB2016101207 - SQL injection in Network Level Service
Published: October 12, 2016 Updated: October 13, 2016
Security Bulletin ID
SB2016101207
Severity
High
Patch available
NO
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Code execution
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) SQL injection (CVE-ID: CVE-2016-6443)
The vulnerability allow a remote authenticated user to perform SQL injection attack and affect target system confidentiality.The weakness is caused by insufficient validation of user-supplied input within SQL queries. By sending a specially crafted URLs containing malicious SQL statements, attackers can define database values.
Successful exploitation of the vulnerability will result in compromise of confidentiality. Repeated exploitation may cause denial of service on the vulnerable system.
Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.