CVE-2015-20122 | Yonyou A6 OA File Attachment Download Endpoint downloadAtt.jsp attach_ids sql injection
A vulnerability, which was classified as critical, has been found in Yonyou A6 OA. This affects an unknown function of the file downloadAtt.jsp of the component File Attachment Download Endpoint. The manipulation of the argument attach_ids leads to sql injection.
This vulnerability is traded as CVE-2015-20122. It is possible to initiate the attack remotely. There is no exploit available.VulDB Recent EntriesRead More