# Exploit Title: OmniCenter 12.1.1 – Unauthenticated SQL Injection # Exploit Author: Luis Rios 0x6c72696f73 [at] illumant.com # Website: https://illumant.com # Date: 2019-09-17 # Vendor: Netreo Inc (https://www.netreo.com/) # Software Link: https://www.netreo.com/solutions/server-management/ # Affected Version: <= 12.1.1 & <= 12.0.7 # Patched Version: 12.1.2 & 12.0.8 # Category: Web Application # Platform: Linux # Tested on: Linux + MySQL # CVE: CVE-2019-17128 # Description ######################## OmniCenter 12.1.1 and below (and 12.0.8 and below) is affected by an unauthenticated SQL Injection (Boolean Based Blind). The injection allows an attacker to read sensitive information from the database used by the application. # Timeline ######################## 09/17/2019 Discovery 09/18/2019 Contact with vender 10/01/2019 Patch Released (https://kb.netreo.com/oc12/omnicenter-12-1-2/) 10/02/2019 Request ID CVE 10/03/2019 Assigned CVE-2019-17128 10/04/2019 Vendor granted permission to publicly disclose 10/04/2019 Public disclosure # About Illumant ######################## Illumant has conducted thousands of security assessment and compliance engagements, helping over 800 clients protect themselves from cyber-attacks. Through meticulous manual analysis, Illumant helps companies navigate the security and threat landscape to become more secure, less of a target, and more compliant. For more information, visit https://illumant.com/