TGViewer
Netlas.io Netlas.io @netlas · 2.33K subscribers
Post #133 927
CVE-2023-39336: SQL injection and RCE in Ivanti EPM, 9.6 rating 🔥

An attacker can use SQL injection without authentication. Additionally, if the core server is configured to use Microsoft SQL Express, this might lead to RCE on the core server.

Search at Netlas.io:
👉🏻 Link: https://nt.ls/fSOY9
👉🏻 Dork: http.headers.set_cookie:("JSESSIONID" "Path" "/mifs")

Vendor's advisory: https://forums.ivanti.com/s/article/SA-2023-12-19-CVE-2023-39336?language=en_US
  • 🔥 6
  • 👾 4
  • 👍 2
More from @netlas
  1. Oct 5, 2026CVE-2026-96940: EoP vulnerability in MS Exchange Server, 8.8 rating ‍🔥 Microsoft has upda…
  2. Oct 2, 2026CVE-2026-63292 and others: Multiple vulnerabilities in Apache HTTP Server, up to 9.8 ratin…
  3. Sep 29, 2026CVE-2026-88771 & CVE-2026-88772: RCE and/or DoS in Citrix NetScaler ADC and NetScaler Gate…
  4. Sep 25, 2026CVE-2026-13016 and others: Multiple vulnerabilities in ServiceNow, up to 9.3 Rating 🔥 Rec…
  5. Sep 24, 2026CVE-2026-88804: Unauthenticated update of public UI settings leading to stored XSS in Ranc…
  6. Sep 23, 2026CVE-2026-87902: Path Traversal in WordPress leading to RCE, 9.2 Rating 🔥 Another newly di…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →