#VU47082 Input validation error in Ozeki NG SMS Gateway - CVE-2020-14027
Published: September 22, 2020 / Updated: September 24, 2020
Ozeki NG SMS Gateway
Ozeki Ltd.
Description
The vulnerability allows a remote attacker to compromise the application.
The vulnerability exists due to the database connection strings accept custom unsafe arguments, such as ENABLE_LOCAL_INFILE. A remote attacker can force the application to connect to a database server under attacker control and gain full access to the application.