CVE-2017-9848

Publication date

2017-06-24 17:00:00

Family

mitre

State

PUBLISHED

Description

SQL injection vulnerability in C_InfoService.asmx in WebServices in Easysite 7.0 could allow remote attackers to execute arbitrary SQL commands via an XML document containing a crafted ArticleIDs element within a GetArticleHitsArray element.