Jinher Network OA SQL Injection Vulnerability in NetDiskProperty.aspx

Vulnerability

A critical SQL injection vulnerability has been identified in Jinher Network OA C6, specifically in the file '/C6/JHSoft.Web.NetDisk/NetDiskProperty.aspx'. The vulnerability arises from the manipulation of the 'id' argument, allowing remote attackers to inject malicious SQL commands. This exploitation could lead to unauthorized access to sensitive data. The vulnerability has been publicly disclosed, and a proof-of-concept exploit is available.

Impact

Exploitation of this vulnerability allows for SQL injection, where an attacker can manipulate database queries. This could lead to unauthorized data access, data manipulation, or in some cases, executing administrative operations on the database.

Reproduction

The vulnerability can be reproduced by sending a GET request to '/C6/JHSoft.Web.NetDisk/NetDiskProperty.aspx' with a crafted 'id' parameter that includes SQL injection payloads. The injected SQL code is executed by the application, allowing the attacker to manipulate the database. After the injection, the response can be analyzed to confirm the exploitation, such as by extracting database information or causing a delay in the response, indicating successful injection.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.7
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.