HGiga EIP product 存在SQL注入漏洞,攻击者可利用该漏洞可以将SQL命令注入到特定的URL参数(文档管理页面)中,获取数据库模式和数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| HGiga | OAKSv20 OAKlouds-document_v3 2.0 | unspecified ~ 2.0-54 | - |
|
| HGiga | OAKSv30 OAKlouds-document_v3 3.0 | unspecified ~ 3.0-54 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-22852 | 8.8 HIGH | HGiga OAKloud Portal - SQL injection -2 |
| CVE-2021-22850 | 5.3 MEDIUM | HGiga OAKloud Portal - Security Misconfiguration |
No comments yet