CVE-2019-1000023
04.02.2019, 21:29
OPT/NET BV OPTOSS Next Gen Network Management System (NG-NetMS) version v3.6-2 and earlier versions contains a SQL Injection vulnerability in Identified vulnerable parameters: id, id_access_type and id_attr_access that can result in a malicious attacker can include own SQL commands which database will execute. This attack appears to be exploitable via network connectivity.
Vendor | Product | Version |
---|---|---|
opt-net | ng-netms | 𝑥 ≤ 3.6-2 |
𝑥
= Vulnerable software versions
References