Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2019-18663

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

ARP-GUARD是一套网络访问控制解决方案。 ARP-GUARD 4.0.0-5版本中的/login/forgot1 POST请求存在SQL注入漏洞。远程攻击者可借助‘user_id’参数利用该漏洞执行任意SQL命令。

AI Predicted 9.8 Difficulty: Easy EPSS 1.43% · P71
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2019-18663

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
A SQL injection vulnerability in a /login/forgot1 POST request in ARP-GUARD 4.0.0-5 allows unauthenticated remote attackers to execute arbitrary SQL commands via the user_id parameter.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
ARP-GUARD SQL注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
ARP-GUARD是一套网络访问控制解决方案。 ARP-GUARD 4.0.0-5版本中的/login/forgot1 POST请求存在SQL注入漏洞。远程攻击者可借助‘user_id’参数利用该漏洞执行任意SQL命令。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2019-18663

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2019-18663

登录查看更多情报信息。

Security Blog Posts for CVE-2019-18663 (1)

Same Patch Batch · n/a · 2019-11-04 · 23 CVEs total

CVE-2019-18178 Real Time Engineers FreeRTOS+FAT 资源管理错误漏洞
CVE-2010-3669 TYPO3 跨站脚本漏洞
CVE-2010-3668 TYPO3 注入漏洞
CVE-2010-3667 TYPO3 输入验证错误漏洞
CVE-2010-3666 TYPO3 安全特征问题漏洞
CVE-2010-3665 TYPO3 跨站脚本漏洞
CVE-2010-3664 TYPO3 信息泄露漏洞
CVE-2010-3663 TYPO3 代码问题漏洞
CVE-2010-3662 TYPO3 SQL注入漏洞
CVE-2015-8980 php-gettext 安全漏洞
CVE-2019-17210 ARM Mbed OS MQTT library 输入验证错误漏洞
CVE-2019-18680 Linux kernel 代码问题漏洞
CVE-2019-13497 One Identity Cloud Access Manager 跨站请求伪造漏洞
CVE-2019-13496 One Identity Cloud Access Manager 安全漏洞
CVE-2019-18684 Sudo 竞争条件问题漏洞
CVE-2013-2261 Cryptocat 信息泄露漏洞
CVE-2013-4104 Cryptocat 加密问题漏洞
CVE-2019-18683 Linux kernel 资源管理错误漏洞
CVE-2013-4100 Cryptocat 输入验证错误漏洞
CVE-2013-4101 Cryptocat 输入验证错误漏洞

Showing top 20 of 23 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2019-18663

No comments yet


Leave a comment