CVE-2023-39336: SQL injection and RCE in Ivanti EPM, 9.6 rating 🔥
An attacker can use SQL injection without authentication. Additionally, if the core server is configured to use Microsoft SQL Express, this might lead to RCE on the core server.
Search at Netlas.io:
👉🏻 Link: https://nt.ls/fSOY9
👉🏻 Dork: http.headers.set_cookie:("JSESSIONID" "Path" "/mifs")
Vendor's advisory: https://forums.ivanti.com/s/article/SA-2023-12-19-CVE-2023-39336?language=en_US
Post #133
927

- 🔥 6
- 👾 4
- 👍 2