Description
Multiple SQL injection vulnerabilities in NICE Recording eXpress (aka Cybertech eXpress) 6.5.7 and earlier allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
References (2)
Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
http://packetstormsecurity.com/files/126858/NICE-Recording-eXpress-6.x-Root-Backdoor-XSS-Bypass.html
Scores
EPSS
0.0188
EPSS Percentile
77.3%
Details
CWE
CWE-89
Status
published
Products (2)
nice/recording_express
6.3.5
nice/recording_express
< 6.5.7
Published
Jun 18, 2014
Tracked Since
Feb 18, 2026