SQL Injection Vulnerabilities in MicroDigital N-Series Cameras: Exploiting HTTPD for Unauthorized Admin Account Creation

SQL Injection Vulnerabilities in MicroDigital N-Series Cameras: Exploiting HTTPD for Unauthorized Admin Account Creation

CVE-2019-14702 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. SQL injection vulnerabilities exist in 13 forms that are reachable through HTTPD. An attacker can, for example, create an admin account.

Learn more about our Cis Benchmark Audit For Microsoft Sql Server.