SQL Injection in Advanced InfoData Systems (AIS) ESEL-Server 67 (which is the backend for the AIS logistics mobile app) allows an anonymous attacker to execute arbitrary code in the context of the user of the MSSQL database. The default user for the database is the 'sa' user.
References
Link Resource
https://github.com/rapid7/metasploit-framework/pull/11641/ Exploit Third Party Advisory
https://www.ais.de Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2019-05-31T21:42:37

Updated: 2019-05-31T21:42:37

Reserved: 2019-03-27T00:00:00


Link: CVE-2019-10123

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2019-05-31T22:29:01.223

Modified: 2019-06-03T15:20:21.550


Link: CVE-2019-10123

JSON object: View

cve-icon Redhat Information

No data.

CWE