CVE-2017-10899: SQL Injection
Published Dec 1, 2017
·Updated
SQL injection vulnerability in the A-Reserve and A-Reserve for MT cloud versions 3.8.6 and earlier allows an attacker to execute arbitrary SQL commands via unspecified vectors.
Affected Software
2 affected components
Ark-web A-reserve<=3.8.6
Ark-web A-reserve Movabletype<=3.8.6
Event History
Dec 1, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-10899?
The severity of CVE-2017-10899 is considered high due to the potential for arbitrary SQL command execution.
2
How do I fix CVE-2017-10899?
To fix CVE-2017-10899, upgrade to A-Reserve version 3.8.7 or later.
3
What software versions are affected by CVE-2017-10899?
CVE-2017-10899 affects A-Reserve versions 3.8.6 and earlier.
4
What type of vulnerability is CVE-2017-10899?
CVE-2017-10899 is an SQL injection vulnerability.
5
What can attackers do with CVE-2017-10899?
Attackers can execute arbitrary SQL commands through unspecified vectors in affected versions.