CVE-2020-35276

EgavilanMedia ECM Address Book 1.0 is affected by SQL injection. An attacker can bypass the Admin Login panel through SQLi and get Admin access and add or remove any user.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:egavilanmedia:ecm_address_book:1.0:*:*:*:*:*:*:*

Information

Published : 2020-12-21 07:15

Updated : 2020-12-23 12:23


NVD link : CVE-2020-35276

Mitre link : CVE-2020-35276


JSON object : View

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Advertisement

dedicated server usa

Products Affected

egavilanmedia

  • ecm_address_book