Petraware pTransformer ADC versions prior to 2.1.7.22827 suffer from a remote SQL injection vulnerability that allows for login bypass.
be5cf0e4686ee81291a49394c74a1db3d5f2794df10cc646e837e51258c6be83
# Exploit Title: Petraware pTransformer ADC before 2.1.7.22827 allows SQL
Injection via the User ID parameter to the login form.
# Date: 28-05-2019
# Exploit Author: Faudhzan Rahman
# Website: https://faudhzanrahman.blogspot.com/
# Vendor Homepage: http://www.petraware.com
# Version: 2.0
# CVE : CVE-2019-12372
# Tested on: Windows 10 Pro
*Description*
The login form on pTransformer ADC does not filter dangerous character such
as single quote ('). This has cause the application to be vulnerable to SQL
Injection.
*Proof-of-concept*
The vulnerable parameter is User ID. By injecting ' or '1'='1'-- ,it will
bypass the login form.
*Reference*
https://faudhzanrahman.blogspot.com/2019/05/sql-injection-on-login-form.html