nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-16659 CVE-2018-16659
CRITICAL
Rausoft ID.prove 2.95 - 'Username' SQL injection
Record summary
CVE-2018-16659 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
An issue was discovered in Rausoft ID.prove 2.95. The login page allows SQL injection via Microsoft SQL Server stacked queries in the Username POST parameter. Hypothetically, an attacker can utilize master..xp_cmdshell for the further privilege elevation.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBRausoft ID.prove 2.95 - 'Username' SQL injectionExploitDB exploitby Ilya TimchenkoNot analyzed1 file
References
245500exploit
https://www.exploit-db.com/exploits/45500