Advantech WebAccess updateTemplate.aspx SQL Injection (CVE-2017-5154)

An SQL injection vulnerability has been reported in Advantech WebAccess. The vulnerability is due to insufficient validation of the template parameter in HTTP request sent to the updateTemplate.aspx. A remote attacker could exploit this vulnerability by sending a HTTP request with a malicious SQL query to the target server. Successful exploitation could allow the attacker to access and modify potentially sensitive information.

Leave a Reply