CVE-2019-10123
CRITICALAIS logistic_software < 67 - Unauthenticated SQL Injection
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2019-10123.
PoCs published by Metasploit, Manuel Feifel, including Metasploit module exploits/windows/misc/ais_esel_server_rce.
AI-analyzed exploit summary This Metasploit module exploits an unauthenticated SQL injection vulnerability in AIS logistics ESEL-Server to achieve remote code execution via `xp_cmdshell`. It leverages a flawed login process to inject arbitrary SQL commands, typically targeting MSSQL servers with the 'sa' user.
Description
SQL Injection in Advanced InfoData Systems (AIS) ESEL-Server 67 (which is the backend for the AIS logistics mobile app) allows an anonymous attacker to execute arbitrary code in the context of the user of the MSSQL database. The default user for the database is the 'sa' user.
Exploits (2)
This Metasploit module exploits an unauthenticated SQL injection vulnerability in AIS logistics ESEL-Server to achieve remote code execution via `xp_cmdshell`. It leverages a flawed login process to inject arbitrary SQL commands, typically targeting MSSQL servers with the 'sa' user.
This Metasploit module exploits an unauthenticated SQL injection vulnerability in AIS logistics ESEL-Server, allowing remote code execution via `xp_cmdshell`. The exploit crafts a malicious login message to inject SQL commands, enabling payload execution on the target system.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H