go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Unisoon UltraLog Express - SQL Injection

TVN ID TVN-201911001
CVE ID CVE-2020-3936
CVSS 10.0 (Critical)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected Products UltraLog Express ver 1.4.0
Description UltraLog Express device management interface does not properly filter user inputted string in some specific parameters, attackers can inject arbitrary SQL command.
Solution Contact Unisoon for vulnerabilities repairment.
Credit Alan Chung(NCCST)
Public Date 2020-03-27
Top