CVE-2017-10937: SQL Injection
Published Jul 25, 2018
·Updated
SQL injection vulnerability in all versions prior to V2.01.05.09 of the ZTE ZXIPTV-UCM product allows remote attackers to execute arbitrary SQL commands via the opertype parameter, resulting in the disclosure of database information.
Affected Software
2 affected components
ZTE Zxiptv-ucm Firmware<2.01.05.09
ZTE ZXIPTV-UCM
Event History
Jul 25, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-10937?
The severity of CVE-2017-10937 is classified as high due to its potential for remote SQL injection attacks.
2
How do I fix CVE-2017-10937?
To fix CVE-2017-10937, update ZTE ZXIPTV-UCM firmware to version 2.01.05.09 or later.
3
What kind of attack does CVE-2017-10937 allow?
CVE-2017-10937 allows remote attackers to execute arbitrary SQL commands, leading to database information disclosure.
4
Which versions of ZTE ZXIPTV-UCM are affected by CVE-2017-10937?
All versions of ZTE ZXIPTV-UCM prior to V2.01.05.09 are affected by CVE-2017-10937.
5
Is the ZTE ZXIPTV-UCM vulnerable by default?
Yes, the ZTE ZXIPTV-UCM is vulnerable by default if it is running a version prior to 2.01.05.09.