Cisco Prime Service Catalog CVE-2017-12364 SQL Injection Vulnerability



Cisco Prime Service Catalog is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.

Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

This issue is being tracked by Cisco Bug ID CSCvg30333.

Information

Bugtraq ID: 102004
Class: Input Validation Error
CVE: CVE-2017-12364

Remote: Yes
Local: No
Published: Nov 29 2017 12:00AM
Updated: Nov 29 2017 12:00AM
Credit: Cisco
Vulnerable: Cisco Prime Service Catalog 12.1
Cisco Prime Service Catalog 12.0
Cisco Prime Service Catalog 11.1.1


Not Vulnerable:

Exploit


Attackers can exploit this issue using a browser.


Related Posts