Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Netreo OmniCenter through 12.1.1 allows unauthenticated SQL Injection (Boolean Based Blind) in the redirect parameters and parameter name of the login page through a GET request. The injection allows an attacker to read sensitive information from the database used by the application.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Netreo OmniCenter SQL注入漏洞
Vulnerability Description
Netreo OmniCenter是美国Netreo公司的一套服务器和网络管理软件。该软件主要用于监控服务器和后端系统状态,并提供警报等功能。 Netreo OmniCenter 12.1.1及之前版本中存在SQL注入漏洞。该漏洞源于基于数据库的应用缺少对外部输入SQL语句的验证。攻击者可利用该漏洞执行非法SQL命令。
CVSS Information
N/A
Vulnerability Type
N/A