Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-70617
HistoryApr 24, 2022 - 12:00 a.m.

Blazer SQL Injection Vulnerability

2022-04-2400:00:00
China National Vulnerability Database
www.cnvd.org.cn
32
blazer
sql injection
vulnerability
validation
web panel
database
exploit
write access

EPSS

0.001

Percentile

31.8%

Blazer is a tool. Allows SQL queries to be executed against a database from a Web panel.A SQL injection vulnerability exists in versions of Blazer prior to 2.6.0, which stems from the application’s lack of validation of externally entered SQL statements. An attacker could exploit this vulnerability to allow users to run queries that they would not normally run. If the data source has write access, this could include modifying the data in some cases.

EPSS

0.001

Percentile

31.8%