CVE-2018-17562

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
03/10/2018
Last modified:
21/11/2018

Description

Multi-Tech FaxFinder before 5.1.6 has SQL Injection via a status/call_details?oid= URI, allowing an attacker to extract the underlying database schema to further disclose other fax server information through different injection points.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:multitech:faxfinder:*:*:*:*:*:*:*:* 5.1.6 (excluding)