CVE-2017-10936
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 1.3%
exploitation probability
1.3%top 30% of all CVEs
observed exploitation
nono source reports it
In short
A flaw in ZTE ZXCDN-SNS lets attackers send specially crafted requests that run unauthorized database commands, exposing sensitive information stored in the system.
Technical detail
SQL injection vulnerability in the aoData parameter allows unauthenticated remote attackers to execute arbitrary SQL queries against the backend database. Affected versions prior to V4.01.01; exploitation results in unauthorized data disclosure and potential database manipulation.
Summary generated and translated by AI from the official description.
SQL injection vulnerability in all versions prior to V4.01.01 of the ZTE ZXCDN-SNS product allows remote attackers to execute arbitrary SQL commands via the aoData parameter, resulting in the disclosure of database information.
Affected products
ZTE · ZXCDN-SNS