Exploitation Summary
EIP tracks 1 public exploit for CVE-2014-9226. PoCs published by SEC Consult.
AI-analyzed exploit summary The exploit demonstrates an unauthenticated SQL injection vulnerability in Symantec Data Center Security: Server Advanced (SDCS:SA) via the /sis-ui/authenticate endpoint, allowing arbitrary SQL execution and SYSTEM-level code execution. It includes a Python script to inject SQL statements that create a new admin user.
Description
The management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x through 6.0 MP1 allows local users to bypass intended Protection Policies via unspecified vectors.
Exploits (1)
The exploit demonstrates an unauthenticated SQL injection vulnerability in Symantec Data Center Security: Server Advanced (SDCS:SA) via the /sis-ui/authenticate endpoint, allowing arbitrary SQL execution and SYSTEM-level code execution. It includes a Python script to inject SQL statements that create a new admin user.