7.5
CVSSv2

CVE-2017-6550

Published: 20/03/2017 Updated: 23/03/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in Kinsey Infor-Lawson (formerly ESBUS) allow remote malicious users to execute arbitrary SQL commands via the (1) TABLE parameter to esbus/servlet/GetSQLData or (2) QUERY parameter to KK_LS9ReportingPortal/GetData.

Vulnerable Product Search on Vulmon Subscribe to Product

kinsey infor-lawson -

Exploits

################################################################## # Exploit Title: Kinsey Infor / Lawson (ESBUS) - Multiple SQL Injections ################################################################## # Date: 3/10/2017 ################################################################## # Exploit Author: Michael Benich ######################## ...
Kinsey's Infor-Lawson (formerly ESBUS) suffers from a remote SQL injection vulnerability ...