CVE-2023-36934: MOVEit Transfer – SQL Injection

CVE-2023-36934: MOVEit Transfer - SQL Injection-渗透云记 - 专注于网络安全与技术分享
CVE-2023-36934: MOVEit Transfer – SQL Injection
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2023-36934: MOVEit TransFEr – SQL Injection

漏洞描述

In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), a SQL injection vulnerability has been identified in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain unauthorized access to the MOVEit Transfer database. An attacker could submit a crafted payload to a MOVEit Transfer application endpoint that could result in modification and disclosure of MOVEit database content.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享