ID

VAR-201608-0493


TITLE

Beijing Dingfeng Gold Technology Co., Ltd. Library System Authentication Bypass Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2016-06607

DESCRIPTION

Beijing Dingfeng Gold Technology Co., Ltd. library system is widely used in various enterprises and institutions, major schools and other libraries. Including system management, system query, system settings, printing, borrowing books, returning books and other major modules. There is an authentication bypass vulnerability in the library system of Beijing Dingfeng Gold Technology Co., Ltd. The attacker can enter 'or' = 'to log in to the system directly at the login

Trust: 0.6

sources: CNVD: CNVD-2016-06607

IOT TAXONOMY

category:['IoT']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2016-06607

AFFECTED PRODUCTS

vendor:dingfeng goldmodel:library systemscope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2016-06607

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2016-06607
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2016-06607
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2016-06607

EXTERNAL IDS

db:CNVDid:CNVD-2016-06607

Trust: 0.6

sources: CNVD: CNVD-2016-06607

REFERENCES

url:http://loudong.360.cn/vul/info/id/138280

Trust: 0.6

url:https://butian.360.cn/vul/info/qid/qtva-2016-414845

Trust: 0.6

sources: CNVD: CNVD-2016-06607

SOURCES

db:CNVDid:CNVD-2016-06607

LAST UPDATE DATE

2022-05-04T09:23:34.268000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2016-06607date:2016-08-24T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2016-06607date:2016-08-09T00:00:00