CVE-2016-8341

CRITICAL

Ecava IntegraXor <5.0.413.0 - SQL Injection

Title source: llm
STIX 2.1

Description

An issue was discovered in Ecava IntegraXor Version 5.0.413.0. The Ecava IntegraXor web server has parameters that are vulnerable to SQL injection. If the queries are not sanitized, the host's database could be subject to read, write, and delete commands.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/95907
Mitigation, Third Party Advisory, US Government Resource x_refsource_misc
https://ics-cert.us-cert.gov/advisories/ICSA-17-031-02

Scores

CVSS v3 9.8
EPSS 0.0164
EPSS Percentile 74.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (2)
ecava/integraxor 5.0.413.0
n/a/Ecava IntegraXor 5.0.413.0 Ecava IntegraXor 5.0.413.0
Published Feb 13, 2017
Tracked Since Feb 18, 2026