Post #133
927

CVE-2023-39336: SQL injection and RCE in Ivanti EPM, 9.6 rating 🔥
An attacker can use SQL injection without authentication. Additionally, if the core server is configured to use Microsoft SQL Express, this might lead to RCE on the core server.
Search at Netlas.io:
👉🏻 Link: https://nt.ls/fSOY9
👉🏻 Dork: http.headers.set_cookie:("JSESSIONID" "Path" "/mifs")
Vendor's advisory: https://forums.ivanti.com/s/article/SA-2023-12-19-CVE-2023-39336?language=en_US
An attacker can use SQL injection without authentication. Additionally, if the core server is configured to use Microsoft SQL Express, this might lead to RCE on the core server.
Search at Netlas.io:
👉🏻 Link: https://nt.ls/fSOY9
👉🏻 Dork: http.headers.set_cookie:("JSESSIONID" "Path" "/mifs")
Vendor's advisory: https://forums.ivanti.com/s/article/SA-2023-12-19-CVE-2023-39336?language=en_US
- 🔥 6
- 👾 4
- 👍 2












