PDA

View Full Version : SAP MaxDB Pre-Auth Command Execution



newsbot
10-01-2008, 07:28 PM
SAP MaxDB (https://www.sdn.sap.com/irj/sdn/maxdb) is "a commercial and widely known and used database". A vulnerability in MaxDB's system() command allows remote attackers to cause the program to execute arbitrary commands.

http://www.securiteam.com/securitynews/5HP0C00N5S.html