CVE-2016-3675

SQL injection vulnerability in Huawei Policy Center with software before V100R003C10SPC020 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors related to system databases.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:h:huawei:policy_center:-:*:*:*:*:*:*:*
OR cpe:2.3:o:huawei:policy_center_firmware:v100r003c00:*:*:*:*:*:*:*
cpe:2.3:o:huawei:policy_center_firmware:v100r003c10:*:*:*:*:*:*:*

History

21 Nov 2024, 02:50

Type Values Removed Values Added
References () http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160325-01-policycenter-en - Vendor Advisory () http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160325-01-policycenter-en - Vendor Advisory

Information

Published : 2016-04-11 15:59

Updated : 2024-11-21 02:50


NVD link : CVE-2016-3675

Mitre link : CVE-2016-3675

CVE.ORG link : CVE-2016-3675


JSON object : View

Products Affected

huawei

  • policy_center
  • policy_center_firmware
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')