RULE(RULE ID:338163)

Rule General Information
Release Date: 2024-06-25
Rule Name: Jinshan Terminal Security System V9.0 SQL Injection Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Kingsoft Terminal Security is a security product that provides terminal protection for enterprises. It provides preventive measures against malware, viruses and external attacks to help maintain enterprise data and networks. sql injection vulnerability exists on the page of Kingsoft terminal security system V9.0 /inter/update_software_info_v2.php. This vulnerability is caused by the fact that Kingsoft terminal security system does not filter user input effectively and splice it directly into SQL query statements, resulting in SQL injection vulnerability in the system.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.