CVE ID:

CVE-2019-5488

Details:

EARCLINK ESPCMS-P8 has SQL injection in the install_pack/index.php?ac=Member&at=verifyAccount verify_key parameter. install_pack/espcms_public/espcms_db.php may allow retrieving sensitive information from the ESPCMS database.

References:

:http://www.iwantacve.cn/index.php/archives/108/

ZeroDayLab Assigned Tags:

INJECTION ATTACK
SQL INJECTION
INFORMATION COMPROMISE