Back to search
CVE-2017-6550
Published: Mar 20, 2017
Modified: Aug 5, 2024
PUBLISHED
Description
Multiple SQL injection vulnerabilities in Kinsey Infor-Lawson (formerly ESBUS) allow remote attackers to execute arbitrary SQL commands via the (1) TABLE parameter to esbus/servlet/GetSQLData or (2) QUERY parameter to KK_LS9ReportingPortal/GetData.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
96821
vdb-entry
x_refsource_BID
20170310 CVE-2017-6550: Kinsey Infor-Lawson - Multiple SQL Injections
mailing-list
x_refsource_FULLDISC
41577
exploit
x_refsource_EXPLOIT-DB
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now