6.5
CVSSv2

CVE-2017-7952

Published: 16/05/2017 Updated: 13/08/2017
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

INFOR EAM V11.0 Build 201410 has SQL injection via search fields, related to the filtervalue parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

infor enterprise asset management 11.0_build_201410

Exploits

SQL injection in INFOR EAM V110 Build 201410 search fields (web/base/) via filtervalue parameter ------------------- Assigned CVE: CVE-2017-7952 Reproduction steps: ------------------- 1 Log in with your EAM account 2 Go to any page with a search or filter field in it (for example web/base/WSJOBSxmlhttp) 3 Make any search and intercept th ...
INFOR EAM version 110 build 201410 suffers from a remote SQL injection vulnerability ...