← back
CVE-2018-16659

CVE-2018-16659

23Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 2.7%
from disclosure to weapon0 days
Published on NVDSep 28
1st PoCSep 27
exploitation probability
2.7%top 15% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
An issue was discovered in Rausoft ID.prove 2.95. The login page allows SQL injection via Microsoft SQL Server stacked queries in the Username POST parameter. Hypothetically, an attacker can utilize master..xp_cmdshell for the further privilege elevation.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.