CVE-2017-15329
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Huawei UMA V200R001C00 has a SQL injection vulnerability in the operation and maintenance module. An attacker logs in to the system as a common user and sends crafted HTTP requests that contain malicious SQL statements to the affected system. Due to a lack of input validation on HTTP requests that contain user-supplied input, successful exploitation may allow the attacker to execute arbitrary SQL queries.
Huawei UMA V200R001C00 tiene una vulnerabilidad de inyección SQL en el módulo de operación y mantenimiento. Un atacante inicia sesión en el sistema como usuario común y envía peticiones HTTP manipuladas que contienen instrucciones SQL al sistema afectado. Debido a la falta de validación de entradas de peticiones HTTP que contienen entradas proporcionadas por el usuario, la explotación con éxito podría permitir que el atacante ejecute consultas SQL arbitrarias.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-10-14 CVE Reserved
- 2018-02-15 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.huawei.com/en/psirt/security-advisories/2017/huawei-sa-20171116-01-uma-en | 2018-02-26 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Huawei Search vendor "Huawei" | Uma Firmware Search vendor "Huawei" for product "Uma Firmware" | v200r001c00 Search vendor "Huawei" for product "Uma Firmware" and version "v200r001c00" | - |
Affected
| in | Huawei Search vendor "Huawei" | Uma Search vendor "Huawei" for product "Uma" | - | - |
Safe
|