CVE-2018-14066

The content://wappush content provider in com.android.provider.telephony, as found in some custom ROMs for Android phones, allows SQL injection. One consequence is that an application without the READ_SMS permission can read SMS messages. This affects Infinix X571 phones, as well as various Lenovo phones (such as the A7020) that have since been fixed by Lenovo.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:google:android:7.0:*:*:*:*:*:*:*
cpe:2.3:h:infinixmobility:infinix_x571:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:google:android:6.0:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:lenovo_a7020:-:*:*:*:*:*:*:*

History

21 Nov 2024, 03:48

Type Values Removed Values Added
References () https://hacked0x90.wordpress.com/2018/07/12/lenovo-infinix-sql-injection-to-mobile-sms-leakage/ - Exploit, Third Party Advisory () https://hacked0x90.wordpress.com/2018/07/12/lenovo-infinix-sql-injection-to-mobile-sms-leakage/ - Exploit, Third Party Advisory

Information

Published : 2018-07-15 16:29

Updated : 2024-11-21 03:48


NVD link : CVE-2018-14066

Mitre link : CVE-2018-14066

CVE.ORG link : CVE-2018-14066


JSON object : View

Products Affected

lenovo

  • lenovo_a7020

infinixmobility

  • infinix_x571

google

  • android
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')