A SQL Injection vulnerability in... CVE-2021-36385

10.0 AV AC AU C I A
发布: 2021-08-24
修订: 2024-11-21

A SQL Injection vulnerability in Cerner Mobile Care 5.0.0 allows remote unauthenticated attackers to execute arbitrary SQL commands via a Fullwidth Apostrophe (aka U+FF07) in the default.aspx User ID field. Arbitrary system commands can be executed through the use of xp_cmdshell.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息