SQL injection vulnerability in all versions prior to V2.01.05.09 of the ZTE ZXIPTV-UCM product allows remote malicious users to execute arbitrary SQL commands via the opertype parameter, resulting in the disclosure of database information.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
zte zxiptv-ucm_firmware |