Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-44161— Changing Information Technology Inc. MOTP(Mobile One Time Password) - SQL Injection

CVSS 8.8 · High EPSS 0.19% · P41
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2021-44161

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Changing Information Technology Inc. MOTP(Mobile One Time Password) - SQL Injection
Source: NVD (National Vulnerability Database)
Vulnerability Description
Changing MOTP (Mobile One Time Password) system’s specific function parameter has insufficient validation for user input. A attacker in local area network can perform SQL injection attack to read, modify or delete backend database without authentication.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Source: NVD (National Vulnerability Database)
Vulnerability Title
panorama Mobile One Time Password SQL注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
panorama Mobile One Time Password(MOTP)是中国全景(panorama)公司的一个行动动态密码系统。拥有坚固的双因素身分认证机制,透过OTP动态密码不断更换的特性,有效解决帐号、密码被盗的问题,确保网路交易与组织内部网路的安全性,并可依照客户需求及产业属性给予专属的介接服务。 panorama Mobile One Time Password 中存在SQL注入漏洞,该漏洞源于产品的特定功能参数未对用户输入数据做有效验证。攻击者可通过该漏洞进行执行恶意SQL语句。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
ChangingMOTP(Mobile One Time Password) next of 3.5 ~ unspecified -

II. Public POCs for CVE-2021-44161

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2021-44161

登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2021-44161

No comments yet


Leave a comment