← Volver a CVEs
CVE-2017-10816
CRITICAL9.8
Descripcion
SQL injection vulnerability in the MaLion for Windows and Mac 5.0.0 to 5.2.1 allows remote attackers to execute arbitrary SQL commands via Relay Service Server.
Detalles CVE
Puntuacion CVSS v3.19.8
SeveridadCRITICAL
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado8/4/2017
Ultima modificacion4/20/2025
Fuentenvd
Avistamientos honeypot0
Productos afectados
intercom:malion
Debilidades (CWE)
CWE-89
Referencias
http://www.intercom.co.jp/information/2017/0801.html(vultures@jpcert.or.jp)
https://jvn.jp/en/vu/JVNVU91587298/index.html(vultures@jpcert.or.jp)
http://www.intercom.co.jp/information/2017/0801.html(af854a3a-2127-422b-91ae-364da2661108)
https://jvn.jp/en/vu/JVNVU91587298/index.html(af854a3a-2127-422b-91ae-364da2661108)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.