CVE-2017-16716: SQL Injection
Published Jan 5, 2018
·Updated
A SQL Injection issue was discovered in WebAccess versions prior to 8.3. WebAccess does not properly sanitize its inputs for SQL commands.
Affected Software
1 affected component
Advantech WebAccess<8.3
Event History
Jan 5, 2018
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-16716?
CVE-2017-16716 is rated as a high severity vulnerability due to its potential impact on database security.
2
How do I fix CVE-2017-16716?
To fix CVE-2017-16716, upgrade WebAccess to version 8.3 or later, which includes proper input sanitization for SQL commands.
3
What are the potential impacts of CVE-2017-16716?
The potential impacts of CVE-2017-16716 include unauthorized data access and manipulation through SQL injection.
4
Which versions of WebAccess are affected by CVE-2017-16716?
WebAccess versions prior to 8.3 are affected by CVE-2017-16716.
5
Is CVE-2017-16716 a remote exploit?
CVE-2017-16716 can be exploited remotely if an attacker has access to the WebAccess interface.