Emuse - eServices / eNvoice SQL injection can be used in various ways ranging from bypassing login authentication or dumping the whole database to full RCE on the affected endpoints. The SQLi caused by CWE-209: Generation of Error Message Containig Sensetive Information, showing parts of the aspx code and the webroot location , information an attacker can leverage to further compromise the host.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.gov.il/en/departments/faq/cve_advisories |
|
History
Mon, 16 Sep 2024 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Emuse - eServices / eNvoice SQL injection | Emuse - eServices / eNvoice SQL injection |
Status: PUBLISHED
Assigner: INCD
Published: 2021-12-29T14:13:38.766729Z
Updated: 2024-09-16T18:38:48.510Z
Reserved: 2021-07-12T00:00:00
Link: CVE-2021-36722
No data.
Status : Modified
Published: 2021-12-29T15:15:07.757
Modified: 2024-11-21T06:13:58.780
Link: CVE-2021-36722
No data.