ZeroHour
Full Disclosurepublished ()ingested
Part of a story covered by 2 sources: “0day Rubbish discloses two CVSS 9.8 unauthenticated SOAP command-execution flaws: DBxtra .NET 13.1.1.0 and Jitterbit Agent 12.8.1.6 (Docker)” — merged summary and timeline →

[0day-rubbish] DBxtra .NET 13.1.1.0 Unauthenticated SOAP API to xp_cmdshell code execution (9.8)

highVulnerabilityimportance 40
AI summary · glm-5.3-flash

0day Rubbish disclosed an unauthenticated SOAP API flaw in DBxtra .NET 13.1.1.0 enabling xp_cmdshell command execution, rated CVSS 9.8.

The 0day Rubbish Research Team disclosed an unauthenticated remote code execution vulnerability in DBxtra .NET 13.1.1.0, classified as CWE-306 (missing authentication). The flaw is reachable via the unauthenticated SOAP API and abuses SQL Server's xp_cmdshell to run operating system commands. It is rated CVSS 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). No CVE identifier or exploitation evidence was provided in the disclosure.

  • Unauthenticated SOAP API leads to code execution (CWE-306)
  • Abuses SQL Server xp_cmdshell for OS command execution
  • CVSS 9.8 with no privileges or user interaction required
  • Affects DBxtra .NET version 13.1.1.0
Full article

Posted by disclosure via Fulldisclosure on Sep 08 TO: fulldisclosure () seclists org SUBJECT: [0day-rubbish] DBxtra .NET 13.1.1.0 Unauthenticated SOAP API to xp_cmdshell code execution (9.8) FROM: disclosure () 0day-rubbish com ----BODY---- 0day Rubbish Research Team is publicly disclosing a vulnerability in DBxtra .NET 13.1.1.0. Type: Unauthenticated SOAP API to xp_cmdshell code execution (CWE-306) CVSS: 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) Impact: unauthenticated remote code execution as...

This source does not provide full text. Read it at seclists.org.