ID

VAR-201706-1138


TITLE

SQL injection vulnerability in mode parameter of GetBoxyStatus.ashx file in ioffice OA system

Trust: 0.6

sources: CNVD: CNVD-2017-06131

DESCRIPTION

Hongfan Computer Technology Co., Ltd. is a high-tech enterprise controlled by CSSC Marine and Defense Equipment Co., Ltd. (CSIC Defense), and is an important part of the state-level technology center. The ioffice OA system involves hospital, government, military, and group industries. There is a SQL injection vulnerability in the mode parameter of the GetBoxyStatus.ashx file in the ioffice OA system, which is caused by the failure to effectively filter the parameters submitted by the user. An attacker could use the vulnerability to access or modify database data.

Trust: 0.6

sources: CNVD: CNVD-2017-06131

IOT TAXONOMY

category:['IoT']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2017-06131

AFFECTED PRODUCTS

vendor:hongfan computermodel:ioffice oa systemscope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2017-06131

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2017-06131
value: HIGH

Trust: 0.6

CNVD: CNVD-2017-06131
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:C/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2017-06131

PATCH

title:SQL Injection Vulnerability in Mode Parameter of GetBoxyStatus.ashx File in iOffice Systemurl:https://www.cnvd.org.cn/patchinfo/show/93116

Trust: 0.6

sources: CNVD: CNVD-2017-06131

EXTERNAL IDS

db:CNVDid:CNVD-2017-06131

Trust: 0.6

sources: CNVD: CNVD-2017-06131

SOURCES

db:CNVDid:CNVD-2017-06131

LAST UPDATE DATE

2022-05-04T09:29:32.990000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2017-06131date:2017-05-10T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2017-06131date:2017-06-19T00:00:00