ID

VAR-201603-0401


TITLE

There are SQL injection vulnerabilities in Guanqun Jinchen anti-virus wall gateway device

Trust: 0.6

sources: CNVD: CNVD-2016-07163

DESCRIPTION

An anti-virus gateway is a network device that protects the security of incoming and outgoing data within a network (typically a local area network). There is a SQL injection vulnerability in the Guanqun Jinchen anti-virus wall gateway device. The vulnerability parameter is sth, which allows an attacker to exploit common vulnerabilities to obtain database sensitive information. The vulnerability URL is: https://106.39.115.3:443/index.php?action=relogin&nickname=anoeloff&sth=522&warning=%B5%C7%C2%BC%CA%A7%B0%DC%A3%A1%D3%C3 %BB%A7%C3%FB%BB%F2%C3%DC%C2%EB%B4%ED%CE%F3%A3%AC%C7%EB%C1%AA%CF%B5%CF%B5%CD %B3%B9%DC%C0%ED%D4%B1%A3%A1<br>Login%20failed!%20username%20or%20password%20error, Please%20contact%20system%20administrators!

Trust: 0.6

sources: CNVD: CNVD-2016-07163

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2016-07163

AFFECTED PRODUCTS

vendor:guanqun jinchenmodel:anti-virus wall gateway equipmentscope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2016-07163

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2016-07163
value: HIGH

Trust: 0.6

CNVD: CNVD-2016-07163
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:C/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2016-07163

EXTERNAL IDS

db:WOOYUNid:WOOYUN-2015-0140977

Trust: 0.6

db:CNVDid:CNVD-2016-07163

Trust: 0.6

sources: CNVD: CNVD-2016-07163

REFERENCES

url:http://www.wooyun.org/bugs/wooyun-2015-0140977

Trust: 0.6

sources: CNVD: CNVD-2016-07163

SOURCES

db:CNVDid:CNVD-2016-07163

LAST UPDATE DATE

2022-05-17T01:46:30.361000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2016-07163date:2016-09-04T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2016-07163date:2016-03-14T00:00:00