6SHR system from Gether Technology does not properly validate the specific page parameter, allowing remote attackers with regular privilege to inject SQL command to read, modify, and delete database contents.
References
Link | Resource |
---|---|
https://www.twcert.org.tw/en/cp-139-8034-657b7-2.html | Vendor Advisory |
https://www.twcert.org.tw/tw/cp-132-8030-e2eac-1.html | Vendor Advisory |
Configurations
History
05 Sep 2024, 13:40
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:6shr_system_project:6shr_system:*:*:*:*:*:*:*:* | |
Summary |
|
|
First Time |
6shr System Project
6shr System Project 6shr System |
|
References | () https://www.twcert.org.tw/en/cp-139-8034-657b7-2.html - Vendor Advisory | |
References | () https://www.twcert.org.tw/tw/cp-132-8030-e2eac-1.html - Vendor Advisory |
30 Aug 2024, 03:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-08-30 03:15
Updated : 2024-09-05 13:40
NVD link : CVE-2024-8329
Mitre link : CVE-2024-8329
CVE.ORG link : CVE-2024-8329
JSON object : View
Products Affected
6shr_system_project
- 6shr_system
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')