Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A vulnerability has been identified in Desigo Insight (All versions). The web service does not properly apply input validation for some query parameters in a reserved area. This could allow an authenticated attacker to retrieve data via a content-based blind SQL injection attack.
CVSS Information
N/A
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Vulnerability Title
Siemens DESIGO INSIGHT SQL注入漏洞
Vulnerability Description
Siemens DESIGO INSIGHT是德国西门子(Siemens)公司的一款热网监控软件平台。该软件可实现换热站的远程监控,并上传至调度中心,还具有报警记录、日志记录、趋势记录和报表功能。。 Desigo Insight 所有版本存在SQL注入漏洞,该漏洞源于web服务没有正确地为某些查询参数应用输入验证,攻击者可利用该漏洞通过基于内容的盲SQL注入攻击来检索数据。
CVSS Information
N/A
Vulnerability Type
N/A