CVE-2020-3936

UltraLog Express device management interface does not properly filter user inputted string in some specific parameters, attackers can inject arbitrary SQL command.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:unisoon:ultralog_express_firmware:1.4.0:*:*:*:*:*:*:*
cpe:2.3:h:unisoon:ultralog_express:-:*:*:*:*:*:*:*

History

21 Nov 2024, 05:31

Type Values Removed Values Added
References () https://www.twcert.org.tw/tw/cp-132-3451-7d9f0-1.html - Third Party Advisory () https://www.twcert.org.tw/tw/cp-132-3451-7d9f0-1.html - Third Party Advisory
CVSS v2 : 7.5
v3 : 9.8
v2 : 7.5
v3 : 10.0

16 Sep 2024, 23:15

Type Values Removed Values Added
Summary (en) UltraLog Express device management interface does not properly filter user inputted string in some specific parameters, attackers can inject arbitrary SQL command. (en) UltraLog Express device management interface does not properly filter user inputted string in some specific parameters, attackers can inject arbitrary SQL command.

06 May 2024, 10:15

Type Values Removed Values Added
Summary (en) UltraLog Express device management interface does not properly filter user inputted string in some specific parameters, attackers can inject arbitrary SQL command. (en) UltraLog Express device management interface does not properly filter user inputted string in some specific parameters, attackers can inject arbitrary SQL command.

Information

Published : 2020-03-27 04:15

Updated : 2024-11-21 05:31


NVD link : CVE-2020-3936

Mitre link : CVE-2020-3936

CVE.ORG link : CVE-2020-3936


JSON object : View

Products Affected

unisoon

  • ultralog_express_firmware
  • ultralog_express
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')