CVE-2013-3577

Wave EMBASSY Remote Administration Server Help Desk - SQL Injection via Search Field Parameter

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in the Help Desk application in Wave EMBASSY Remote Administration Server (ERAS) allows remote attackers to execute arbitrary SQL commands via the ct100$4MainController$TextBoxSearchValue parameter (aka the search field).

References (1)

Core 1
Core References
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/217836

Scores

EPSS 0.0126
EPSS Percentile 66.5%

Details

CWE
CWE-89
Status published
Products (2)
wave/embassy_remote_administration_server
wave/embassy_remote_administration_server_help_desk
Published Jul 15, 2013
Tracked Since Feb 18, 2026