Description
Multiple SQL injection vulnerabilities in Maxsi eVisit Analyst allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) idsp1.pl, (2) ip.pl, and (3) einsite_director.pl. NOTE: this issue can be leveraged for path disclosure from resulting error messages.
References (10)
Core 10
Core References
Various Sources x_refsource_misc
http://www.portcullis.co.uk/uplds/advisories/easql%2006-057.txt
Various Sources x_refsource_misc
http://www.nth-dimension.org.uk/pub/Portcullis-06-057.txt
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://www.osvdb.org/36113
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/35482
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://www.osvdb.org/36112
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/26110
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://www.osvdb.org/36114
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/24849
Third Party Advisory mailing-list
x_refsource_vim
http://www.attrition.org/pipermail/vim/2007-July/001716.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/35481
Scores
EPSS
0.0234
EPSS Percentile
81.9%
Details
CWE
CWE-89
Status
published
Products (1)
maxsi/evisit_analyst
Published
Jul 11, 2007
Tracked Since
Feb 18, 2026