PT-2017-9622 · Ecava · Ecava Integraxor

Brian Gorenc

+1

·

Published

2017-02-07

·

Updated

2017-03-01

·

CVE-2016-8341

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ecava IntegraXor version 5.0.413.0
Description The issue concerns SQL injection vulnerability in the Ecava IntegraXor web server. Specifically, parameters are not properly sanitized, which could allow an attacker to execute read, write, and delete commands on the host's database. The getdata parameter is mentioned as being vulnerable to SQL injection, potentially leading to remote code execution.
Recommendations For Ecava IntegraXor version 5.0.413.0, consider restricting access to the getdata parameter in the web server to minimize the risk of exploitation until a patch is available. As a temporary workaround, ensure that all queries are properly sanitized to prevent SQL injection attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-8341
ZDI-17-058
ZDI-17-059

Affected Products

Ecava Integraxor