July 27, 2023, 6:36 p.m. | Evan Grant

Tenable Research Advisories www.tenable.com

Authenticated SQL Injection in Advantech iView

A researcher at Tenable has discovered an authenticated SQL injection vulnerability in Advantech iView < v5.7.4 build 6752. An authenticated remote attacker can bypass checks in com.imc.iview.utils.CUtils.checkSQLInjection() to perform blind SQL injection. For example, the attacker can exploit the vulnerability to retrieve the iView admin password.


Proof of Concept:


A proof of concept will be added to Tenable's poc repo on github (https://github.com/tenable/poc)



Evan Grant
Thu, 07/27/2023 - 14:36

admin advantech build bypass exploit injection password proof researcher sql sql injection tenable vulnerability

Social Engineer For Reverse Engineering Exploit Study

@ Independent study | Remote

Data Privacy Manager m/f/d)

@ Coloplast | Hamburg, HH, DE

Cybersecurity Sr. Manager

@ Eastman | Kingsport, TN, US, 37660

KDN IAM Associate Consultant

@ KPMG India | Hyderabad, Telangana, India

Learning Experience Designer in Cybersecurity (f/m/div.) (Salary: ~113.000 EUR p.a.*)

@ Bosch Group | Stuttgart, Germany

Senior Security Engineer - SIEM

@ Samsara | Remote - US