CVE-2016-6566
CRITICALSungard eTRAKiT3 <3.2.1.17 - SQL Injection
Title source: llmDescription
The valueAsString parameter inside the JSON payload contained by the ucLogin_txtLoginId_ClientStat POST parameter of the Sungard eTRAKiT3 software version 3.2.1.17 is not properly validated. An unauthenticated remote attacker may be able to modify the POST request and insert a SQL query which may then be executed by the backend server. eTRAKiT 3.2.1.17 was tested, but other versions may also be vulnerable.
Exploits (1)
Scores
CVSS v3
9.8
EPSS
0.0504
EPSS Percentile
89.8%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-89
Status
published
Products (1)
sungardas/etrakit3
3.2.1.17
Published
Jul 13, 2018
Tracked Since
Feb 18, 2026