Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Brad Taylor

Researcher fromZero Day Initiative
#22045of 53,633
10.6Total CVSS
Vulnerabilities · 2
Medium
2
PT-2017-14536
5.3
2017-12-20
Ecava · Integraxor · CVE-2017-16733
**Name of the Vulnerable Software and Affected Versions** Ecava IntegraXor versions 6.1.1030.1 and prior **Description** A SQL Injection issue allows an attacker to disclose sensitive information from the database. **Recommendations** For versions 6.1.1030.1 and prior, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2017-14537
5.3
2017-12-20
Ecava · Integraxor · CVE-2017-16735
**Name of the Vulnerable Software and Affected Versions** Ecava IntegraXor versions 6.1.1030.1 and prior **Description** A SQL Injection issue was discovered, which generates an error in the database log. This issue allows for potential information disclosure. **Recommendations** For versions 6.1.1030.1 and prior, consider restricting access to the `getdata` API endpoint until a patch is available. As a temporary workaround, avoid using the `name` parameter in the affected API endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.