CVE-2017-12757
Last modified
CVE-2017-12757 is a vulnerability of currently unknown severity. Certain Ambit Technologies Pvt. Ltd products are affected by: SQL Injection. EPSS estimates a 3.61% chance of exploitation in the next 30 days.
Description
Certain Ambit Technologies Pvt. Ltd products are affected by: SQL Injection. This affects iTech B2B Script 4.42i and Tech Business Networking Script 8.26i and Tech Caregiver Script 2.71i and Tech Classifieds Script 7.41i and Tech Dating Script 3.40i and Tech Freelancer Script 5.27i and Tech Image Sharing Script 4.13i and Tech Job Script 9.27i and Tech Movie Script 7.51i and Tech Multi Vendor Script 6.63i and Tech Social Networking Script 3.08i and Tech Travel Script 9.49. The impact is: Code execution (remote).
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ambittechnologies | Itech B2b Script | 4.42i |
| Ambittechnologies | Itech Business Networking Script | 8.26i |
| Ambittechnologies | Itech Caregiver Script | 2.71i |
| Ambittechnologies | Itech Classifieds Script | 7.41i |
| Ambittechnologies | Itech Dating Script | 3.40i |
| Ambittechnologies | Itech Freelancer Script | 5.27i |
| Ambittechnologies | Itech Image Sharing Script | 4.13i |
| Ambittechnologies | Itech Job Script | 9.27i |
| Ambittechnologies | Itech Movie Script | 7.51i |
| Ambittechnologies | Itech Multi Vendor Script | 6.63i |
| Ambittechnologies | Itech Social Networking Script | 3.08i |
| Ambittechnologies | Itech Travel Script | 9.49 |
References
- http://ambit.comNot Applicable
- http://itech.comProduct
- https://www.exploit-db.com/exploits/42507Exploit, Third Party Advisory, VDB Entry
- http://ambit.comNot Applicable
- http://itech.comProduct
- https://www.exploit-db.com/exploits/42507Exploit, Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-12757?
How severe is CVE-2017-12757?
How do I fix CVE-2017-12757?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-1274IBM Domino 8.5.3, and 9.0 is vulnerable to a stack based ove…
- CVE-2017-12740Siemens LOGO! Soft Comfort (All versions before V8.2) lacks …
- CVE-2017-12741Specially crafted packets sent to port 161/udp could cause a…7.5
- CVE-2017-1275IBM Rational Quality Manager and IBM Rational Collaborative …5.4
- CVE-2017-12754Stack buffer overflow in httpd in Asuswrt-Merlin firmware 38…8.8
- CVE-2017-12756Command inject in transfer from another server in extplorer …
- CVE-2017-12758https://www.joomlaextensions.co.in/ Joomla! Component Appoin…
- CVE-2017-12759Ynet Interactive - http://demo.ynetinteractive.com/soa/ SOA …
- CVE-2017-1276IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0 and 6.0 is vuln…
- CVE-2017-12760Ynet Interactive - http://demo.ynetinteractive.com/mobiketa/…
- CVE-2017-12761http://codecanyon.net/user/Endober WebFile Explorer 1.0 is a…
- CVE-2017-12762In /drivers/isdn/i4l/isdn_net.c: A user-controlled buffer is…9.8
Are you affected by CVE-2017-12757?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
