vendor:
24online Model SMS_2500i
by:
Rahul Raz
7,5
CVSS
HIGH
CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
89
CWE
Product Name: 24online Model SMS_2500i
Affected Version From: 8.3.6 build 9.0
Affected Version To: 8.3.6 build 9.0
Patch Exists: NO
Related CWE: N/A
CPE: 24online Model SMS_2500i
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Ubuntu Linux
2016
SQL Injection In 24 Online Billing API
A non-privileged authenticated user can inject SQL commands on the <base-url>/24online/webpages/myaccount/usersessionsummary.jsp?invoiceid=<numeric-id> &fromdt=dd/mm/yyyy hh:mm:ss&todt= dd/mm/yyyy hh:mm:ss. There is complete informational disclosure over the stored database.
Mitigation:
N/A