CVE-2017-5359
HIGHEasyCom SQL iPlug - Denial of Service via D$EVAL Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-5359. PoCs published by hyp3rlinx.
AI-analyzed exploit summary This exploit demonstrates a denial-of-service vulnerability in SQL iPlug by sending an overly long string via HTTP requests to the 'D$EVAL' parameter on port 7078. The PoC floods the target with multiple connections, each sending a large payload to crash the service.
Description
EasyCom SQL iPlug allows remote attackers to cause a denial of service via the D$EVAL parameter to the default URI.
Exploits (1)
This exploit demonstrates a denial-of-service vulnerability in SQL iPlug by sending an overly long string via HTTP requests to the 'D$EVAL' parameter on port 7078. The PoC floods the target with multiple connections, each sending a large payload to crash the service.
References (6)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H