CVE-2015-8298

CRITICAL

RXTEC RXAdmin UPDATE 06/2012 - SQL Injection

Title source: llm
STIX 2.1

Description

Multiple SQL injection vulnerabilities in the login page in RXTEC RXAdmin UPDATE 06 / 2012 allow remote attackers to execute arbitrary SQL commands via the (1) loginpassword, (2) loginusername, (3) zusatzlicher, or (4) groupid parameter to index.htm, or the (5) rxtec cookie to index.htm.

References (3)

Core 3
Core References
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/134525/RXTEC-RXAdmin-SQL-Injection.html
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2015/Nov/90

Scores

CVSS v3 9.8
EPSS 0.0225
EPSS Percentile 84.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
rxtec/rxadmin 2012 06
Published Sep 24, 2018
Tracked Since Feb 18, 2026