CVE-2018-17562
03.10.2018, 20:29
Multi-Tech FaxFinder before 5.1.6 has SQL Injection via a status/call_details?oid= URI, allowing an attacker to extract the underlying database schema to further disclose other fax server information through different injection points.
Vendor | Product | Version |
---|---|---|
multitech | faxfinder | 𝑥 < 5.1.6 |
𝑥
= Vulnerable software versions