CVE-2016-1393

Description

SQL injection vulnerability in Cisco Cloud Network Automation Provisioner (CNAP) 1.0 and 1.1 allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCuy72175.

Risk Information

Base Score
7.1
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
EPSS Score
Exploitation Probability
0.14

Associated Vulnerability

VulnerabilityOS Platform
Cisco Cloud Network Automation Provisioner SQL Injection Vulnerability For Cisco Cloud Network Automation ProvisionerNCM
Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability (CVE-2016-1393)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234