|
|||
Rule General Information |
---|
Release Date: | 2025-05-14 | |
Rule Name: | Xinet Elegant 6 Asset Lib Web UI 6.1.655 SQL Injection Vulnerability (CVE-2019-19245) | |
Severity: | Critical | |
CVE ID: | CVE-2019-19245 | |
Rule Protection Details |
---|
Description: | NAPC Xinet Elegant 6 Asset Library 6.1.655 allows Pre-Authentication SQL Injection via the /elegant6/login LoginForm[username] field when double quotes are used. | |
Impact: | An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully. | |
Affected OS: | Windows, Linux, Others | |
Reference: | http://hyp3rlinx.altervista.org https://packetstormsecurity.com/files/155505/Xinet-Elegant-6-Asset-Library-Web-Interface-6.1.655-SQL-Injection.html http://hyp3rlinx.altervista.org http://seclists.org/fulldisclosure/2025/Feb/0 |
|
Solutions |
---|
Please contact the software vendor to update the software patch. |