Esri ArcGIS Server是Esri公司的一个面向Web的可用于提供地理位置服务的企业级软件平台。 Esri ArcGIS Server 11.3版本、11.4版本和11.5版本存在SQL注入漏洞,该漏洞源于特定ArcGIS要素服务操作未经验证输入,可能导致SQL注入攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Esri | ArcGIS Server | 11.3 ~ 11.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Esri ArcGIS Server | https://github.com/ByteHawkSec/CVE-2025-57870-POC | POC Details |
No comments yet