CVE-2018-9245
CRITICALEricsson-LG iPECS NMS A.1Ac - SQL Injection via Login Portal User ID and Password Fields
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-9245. PoCs published by Berk Cem Göksel.
AI-analyzed exploit summary This exploit leverages SQL injection (CVE-2018-9245) and incorrect access control (CVE-2018-10285) to dump cleartext database and NMS credentials from Ericsson-LG iPECS NMS. It first bypasses authentication via SQLi, then extracts database credentials, and finally retrieves admin credentials for the NMS.
Description
The Ericsson-LG iPECS NMS A.1Ac login portal has a SQL injection vulnerability in the User ID and password fields that allows users to bypass the login page and execute remote code on the operating system.
Exploits (1)
This exploit leverages SQL injection (CVE-2018-9245) and incorrect access control (CVE-2018-10285) to dump cleartext database and NMS credentials from Ericsson-LG iPECS NMS. It first bypasses authentication via SQLi, then extracts database credentials, and finally retrieves admin credentials for the NMS.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H