Home
CRITICAL: 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NDefault status
unaffected
prior to 2.65
affected
Description
SQL injection vulnerability in DIAL's CentrosNet v2.64. Allows an attacker to retrieve, create, update, and delete databases by sending POST and GET requests with the 'ultralogin' parameter in '/centrosnet/ultralogin.php'.
Problem types
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
prior to 2.65
Credits
Arnau Yepes
References
www.incibe.es/...otices/aviso/sql-injection-dials-centrosnet
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.