ID

VAR-201608-0486


TITLE

There is a SQL injection vulnerability in the transmission of interactive video equipment by Qingliu Xun (Beijing) Technology Co., Ltd.

Trust: 0.6

sources: CNVD: CNVD-2016-05921

DESCRIPTION

StreamOcean, Inc. is the world's leading high-tech company dedicated to the transmission of high-definition interactive video over the Internet. It has a completely independent intellectual property rights, the clear stream video transmission network SOVDN, providing the infrastructure for full video service capabilities. There is a SQL injection vulnerability in the transmission of interactive video equipment by Qingliu Xun (Beijing) Technology Co., Ltd., which allows attackers to obtain sensitive information of the database by using common SQL injection tools.

Trust: 0.6

sources: CNVD: CNVD-2016-05921

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2016-05921

AFFECTED PRODUCTS

vendor:qingliu xunmodel:transmission interactive video equipmentscope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2016-05921

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2016-05921
value: HIGH

Trust: 0.6

CNVD: CNVD-2016-05921
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2016-05921

EXTERNAL IDS

db:WOOYUNid:WOOYUN-2016-0196071

Trust: 0.6

db:CNVDid:CNVD-2016-05921

Trust: 0.6

sources: CNVD: CNVD-2016-05921

REFERENCES

url:http://www.wooyun.org/bugs/wooyun-2016-0196071

Trust: 0.6

sources: CNVD: CNVD-2016-05921

SOURCES

db:CNVDid:CNVD-2016-05921

LAST UPDATE DATE

2022-05-17T01:36:36.559000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2016-05921date:2016-08-04T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2016-05921date:2016-08-03T00:00:00