← Back to CVE List

CVE-2018-16659

Published: 2018-09-28T00:29Z
Last Modified: 2024-11-21T03:53Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
An issue was discovered in Rausoft ID.prove 2.95. The login page allows SQL injection via Microsoft SQL Server stacked queries in the Username POST parameter. Hypothetically, an attacker can utilize master..xp_cmdshell for the further privilege elevation. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt