CVE-2019-10852
EUVD-2019-257923.05.2019, 19:29
Computrols CBAS 18.0.0 allows Authenticated Blind SQL Injection via the id GET parameter, as demonstrated by the index.php?m=servers&a=start_pulling&id= substring.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| computrols | computrols_building_automation_software | 𝑥 ≤ 19.0.0 |
𝑥
= Vulnerable software versions
References