NCR Terminal Handler
cpe:2.3:a:ncr:terminal_handler:*:*:*:*:*:*:*
- 1.5.1
A vulnerability in NCR Terminal Handler version 1.5.1 allows remote attackers to execute arbitrary code and access sensitive information. This is achieved by sending a GET request to the UserService SOAP API endpoint, which validates the existence of a user. The response includes all profile information for valid usernames, including administrative details, while invalid usernames receive a 'User does not exist' message.
Exploitation of this vulnerability allows for arbitrary code execution on the server and unauthorized access to sensitive user information, potentially including administrative data.
To reproduce this vulnerability, send a GET request to the UserService SOAP API endpoint with a valid username. The server will respond with the user's profile information. For an invalid username, the response will indicate that the user does not exist.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.