CVE-2017-5154: SQL Injection
Published Feb 13, 2017
·Updated
An issue was discovered in Advantech WebAccess Version 8.1. To be able to exploit the SQL injection vulnerability, an attacker must supply malformed input to the WebAccess software. Successful attack could result in administrative access to the application and its data files.
Affected Software
1 affected component
Advantech WebAccess=8.1
Event History
Feb 13, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Data Sourced
via NVD·09:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-5154?
CVE-2017-5154 is classified as a high severity SQL injection vulnerability.
2
How do I fix CVE-2017-5154?
To fix CVE-2017-5154, update Advantech WebAccess to a version that addresses this vulnerability.
3
What are the potential impacts of CVE-2017-5154?
Exploitation of CVE-2017-5154 can lead to unauthorized administrative access and exposure of sensitive application data.
4
Who is affected by CVE-2017-5154?
CVE-2017-5154 affects users of Advantech WebAccess version 8.1.
5
How can an attacker exploit CVE-2017-5154?
An attacker can exploit CVE-2017-5154 by supplying malformed input to the WebAccess software.