[0day-rubbish] Gemini 7.3.0 Au... Note

[0day-rubbish] Gemini 7.3.0 Authenticated SQL injection to xp_cmdshell RCE (8.8)

Posted by disclosure via Fulldisclosure on Aug 190day Rubbish Research Team is publicly disclosing a vulnerability in Gemini 7.3.0. Type: Authenticated SQL injection to xp_cmdshell RCE (CWE-89) CVSS: 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) Impact: Authenticated user executes OS commands via stacked SQL and xp_cmdshell as sa/sysadmin Authentication: authenticated Full technical analysis and a reproducible proof-of-concept:...