CVE-2020-3936

UltraLog Express device management interface does not properly filter user inputted string in some specific parameters, attackers can inject arbitrary SQL command.
References
Link Resource
https://www.twcert.org.tw/tw/cp-132-3451-7d9f0-1.html Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:unisoon:ultralog_express_firmware:1.4.0:*:*:*:*:*:*:*
cpe:2.3:h:unisoon:ultralog_express:-:*:*:*:*:*:*:*

History

16 Sep 2024, 23:15

Type Values Removed Values Added
Summary (en) UltraLog Express device management interface does not properly filter user inputted string in some specific parameters, attackers can inject arbitrary SQL command. (en) UltraLog Express device management interface does not properly filter user inputted string in some specific parameters, attackers can inject arbitrary SQL command.

06 May 2024, 10:15

Type Values Removed Values Added
Summary (en) UltraLog Express device management interface does not properly filter user inputted string in some specific parameters, attackers can inject arbitrary SQL command. (en) UltraLog Express device management interface does not properly filter user inputted string in some specific parameters, attackers can inject arbitrary SQL command.

Information

Published : 2020-03-27 04:15

Updated : 2024-09-16 23:15


NVD link : CVE-2020-3936

Mitre link : CVE-2020-3936

CVE.ORG link : CVE-2020-3936


JSON object : View

Products Affected

unisoon

  • ultralog_express_firmware
  • ultralog_express
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')