Vulnerability Details CVE-2013-3578
SQL injection vulnerability in the Help Desk application in Wave EMBASSY Remote Administration Server (ERAS) allows remote authenticated users to execute arbitrary SQL commands via the ct100$4MainController$TextBoxSearchValue parameter (aka the search field), leading to execution of operating-system commands.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 71.1%
CVSS Severity
CVSS v2 Score 9.0
Products affected by CVE-2013-3578
-
cpe:2.3:a:wave:embassy_remote_administration_server:-
-
cpe:2.3:a:wave:embassy_remote_administration_server_help_desk:-