CVE-2017-12710

A SQL Injection issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. By submitting a specially crafted parameter, it is possible to inject arbitrary SQL statements that could allow an attacker to obtain sensitive information.
Configurations

Configuration 1 (hide)

cpe:2.3:a:advantech:webaccess:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2017-08-30 18:29

Updated : 2023-12-10 12:15


NVD link : CVE-2017-12710

Mitre link : CVE-2017-12710

CVE.ORG link : CVE-2017-12710


JSON object : View

Products Affected

advantech

  • webaccess
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')