Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
eMPS 9.0.1.923211 on the Central Management of FireEye EX 3500 devices allows remote authenticated users to conduct SQL injection attacks via the job_id parameter to the email search feature. According to the vendor, the issue is fixed in 9.0.3.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mainway FireEye EX SQL注入漏洞
Vulnerability Description
Mainway FireEye EX是中国九州安域(Mainway)公司的一个应用于企业安全的一体化平台。FireEye? 中央管理平台(CM 系列)是一组管理平台,将 FireEye 产品的管理、报告以及数据共享整合到一个可轻松部署的网络型平台中。中央管理平台可确保实时共享自动生成的威胁情报,以识别并阻止针对组织的先进攻击。 FireEye EX 3500 中的eMPS 9.0.1.923211 存在SQL注入漏洞,该漏洞允许远程认证用户通过job id参数对邮件搜索特性进行SQL注入攻击。
CVSS Information
N/A
Vulnerability Type
N/A