9.8
CVSSv3

CVE-2017-16716

Published: 05/01/2018 Updated: 02/02/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

A SQL Injection issue exists in WebAccess versions before 8.3. WebAccess does not properly sanitize its inputs for SQL commands.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

advantech webaccess

Exploits

#!/usr/bin/python27 # Exploit Title: Advantech WebAccess BWSCADARest Login Method SQL Injection Authentication Bypass Vulnerability # Date: 01-13-2018 # Exploit Author: Chris Lyne (@lynerc) # Vendor Homepage: wwwadvantechcom # Software Link: advcloudfilesadvantechcom/web/Download/webaccess/80/AdvantechWebAccessUSANode80_20150816exe ...
Advantech WebAccess version 80-20150816 suffers from a remote SQL injection vulnerability ...