Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SQL injection vulnerability in ESRI ArcGIS 10.1 allows remote authenticated users to execute arbitrary SQL commands via the where parameter to a query URI for a REST service.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ESRI ArcGIS for Server ‘where’表单域SQL注入漏洞
Vulnerability Description
ArcGIS是美国环境系统研究所(Esri)公司的一套地理信息系统(GIS)软件。该软件提供地图制作、空间数据管理、空间分析、空间信息整合等功能。 ESRI ArcGIS 10.1版本中存在SQL注入漏洞。远程认证攻击者利用该漏洞通过‘where’参数传送到查询URI的REST服务,执行任意SQL命令。
CVSS Information
N/A
Vulnerability Type
N/A