PT-2013-4490 · Wave · Wave Embassy Remote Administration Server
Simone Cecchini
+1
·
Publicado
2013-07-15
·
Atualizado
2013-07-16
·
CVE-2013-3578
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Wave EMBASSY Remote Administration Server (ERAS) (affected versions not specified)
Description
The issue allows remote authenticated users to execute arbitrary SQL commands via the
ct100$4MainController$TextBoxSearchValue parameter, which is the search field in the Help Desk application. This can lead to the execution of operating-system commands.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
OS Command Injection
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Wave Embassy Remote Administration Server