Latest YouTube Video

Tuesday, October 10, 2017

[FD] OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) - SQL Injection

(This is re-submission of corrected advisory due to accidental CVE-ID swapping) Title: OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) - SQL Injection Author: Marcin Woloszyn Date: 27. September 2017 CVE: CVE-2017-14758 Affected Software: ================== OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) Exploit was tested on: ====================== v4.5SP1 Patch 13 (older versions might be affected as well) SQL Injection: ============== Due to lack of prepared statements an application is prone to SQL Injection attacks. Potential attacker can retrieve data from application database by exploiting the issue. Vector :

Source: Gmail -> IFTTT-> Blogger

No comments: