CVE-2018-16659
28.09.2018, 00:29
An issue was discovered in Rausoft ID.prove 2.95. The login page allows SQL injection via Microsoft SQL Server stacked queries in the Username POST parameter. Hypothetically, an attacker can utilize master..xp_cmdshell for the further privilege elevation.
Vendor | Product | Version |
---|---|---|
rausoft | id.prove | 2.95 |
𝑥
= Vulnerable software versions