PT-2013-4490 · Wave · Wave Embassy Remote Administration Server
Simone Cecchini
+1
·
Published
2013-07-15
·
Updated
2013-07-16
·
CVE-2013-3578
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Wave EMBASSY Remote Administration Server (ERAS) (affected versions not specified)
Description
The issue allows remote authenticated users to execute arbitrary SQL commands via the
ct100$4MainController$TextBoxSearchValue parameter, which is the search field in the Help Desk application. This can lead to the execution of operating-system commands.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
OS Command Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wave Embassy Remote Administration Server