vendor:
iPECS NMS
by:
Berk Cem Göksel
8.8
CVSS
HIGH
Multiple SQL injections, Incorrect access control, Sensitive information disclosure
89, 285, 200
CWE
Product Name: iPECS NMS
Affected Version From: A.1Ac
Affected Version To: A.1Ac
Patch Exists: NO
Related CWE: CVE-2018-9245, CVE-2018-10285, CVE-2018-10286
CPE: a:ericsson-lg_enterprise:ipecs_nms
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 2008 R2 x64
2018
Ericsson-LG iPECS NMS – Cleartext Cred. Dump
The Ericsson-LG iPECS NMS version A.1Ac and possibly earlier disclose sensitive information such as cleartext database and NMS login credentials, use incorrect access control mechanisms, are vulnerable to MiTM attacks and are prone to SQL injection attacks on multiple parameters. This script dumps some sensitive information.
Mitigation:
Ensure that the web application is not vulnerable to SQL injection attacks, use secure access control mechanisms, and ensure that sensitive information is not disclosed.