exploit-db-mirror/exploits/jsp/webapps/12242.txt
Offensive Security 36c084c351 DB: 2021-09-03
45419 changes to exploits/shellcodes

2 new exploits/shellcodes

Too many to list!
2021-09-03 13:39:06 +00:00

45 lines
No EOL
773 B
Text

RJ-iTop Network Vulnerability Scanner System Multiple SQL Injection Vulnerabilities
Vulnerable: v3.0.7.x
Vendor: www.rj-itop.com<http://www.rj-itop.com>
Category: Input Validation Error
Impact: SQL injection
Details:
=========
Multiple SQL Injection Vulnerabilities has been found in DRJ-iTop Network Vulnerability Scanner System&#65292; which can be exploited by malicious users to conduct SQL injection and script insertion attacks.
Authentication is required to exploit these vulnerabilities.
POC:
=========
https://8.8.8.8/roleManager.jsp?type=query&id= [SQL Injection]
Timeline:
========
2009.10.19 Report to vendor (but vender did not respond)
2009.11.15 Report to vendor second times
2009.11.19 Report to CNNVD
2010.04.13 Public