CVE-2017-2241

Description

SQL injection vulnerability in the AssetView for MacOS Ver.9.2.0 and earlier versions allows remote attackers to execute arbitrary SQL commands via "File Transfer Web Service".

Risk Information

Base Score
6.3
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
EPSS Score
Exploitation Probability
0.308

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2017-2240,CVE-2017-2241,CVE-2022-28719 are affected in Hammock AssetView 9.2Windows
Vulnerabilities CVE-2017-2240,CVE-2017-2241,CVE-2022-28719 are affected in Hammock Corporation AssetView 9.2Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234