CVE

Id
103370  
CVE No.
CVE-2017-6550  
Status
Candidate  
Description
Multiple SQL injection vulnerabilities in Kinsey Infor-Lawson (formerly ESBUS) allow remote attackers to execute arbitrary SQL commands via the (1) TABLE parameter to esbus/servlet/GetSQLData or (2) QUERY parameter to KK_LS9ReportingPortal/GetData.  
Phase
Assigned (20170308)  
Votes
None (candidate not yet proposed)  
Comments