ID

VAR-201609-0701


TITLE

Chuangda Electronics Co., Ltd. special equipment inspection management system has multiple general-purpose vulnerabilities

Trust: 0.6

sources: CNVD: CNVD-2016-05677

DESCRIPTION

Chuangda Electronics Co., Ltd. is a company that operates camera accessories. There are file reading and SQL injection vulnerabilities in Chuangda Electronics Co., Ltd. special equipment inspection management system. Allows an attacker to use common SQL injection tools to obtain sensitive database information and read arbitrary files.

Trust: 0.6

sources: CNVD: CNVD-2016-05677

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2016-05677

AFFECTED PRODUCTS

vendor:chuangdamodel:electronics co. ltd. special equipment inspection management systemscope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2016-05677

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2016-05677
value: HIGH

Trust: 0.6

CNVD: CNVD-2016-05677
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:C/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2016-05677

EXTERNAL IDS

db:CNVDid:CNVD-2016-05677

Trust: 0.6

sources: CNVD: CNVD-2016-05677

REFERENCES

url:http://loudong.360.cn/vul/info/id/148999;https

Trust: 0.6

sources: CNVD: CNVD-2016-05677

SOURCES

db:CNVDid:CNVD-2016-05677

LAST UPDATE DATE

2022-05-04T09:04:56.502000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2016-05677date:2016-08-03T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2016-05677date:2016-09-22T00:00:00