cvelist/2016/8xxx/CVE-2016-8341.json

67 lines
2.1 KiB
JSON
Raw Normal View History

2017-10-16 12:31:07 -04:00
{
2019-03-18 07:01:07 +00:00
"CVE_data_meta": {
"ASSIGNER": "ics-cert@hq.dhs.gov",
"ID": "CVE-2016-8341",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "Ecava IntegraXor 5.0.413.0",
"version": {
"version_data": [
{
"version_value": "Ecava IntegraXor 5.0.413.0"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
2017-10-16 12:31:07 -04:00
{
2019-03-18 07:01:07 +00:00
"lang": "eng",
"value": "An issue was discovered in Ecava IntegraXor Version 5.0.413.0. The Ecava IntegraXor web server has parameters that are vulnerable to SQL injection. If the queries are not sanitized, the host's database could be subject to read, write, and delete commands."
2017-10-16 12:31:07 -04:00
}
2019-03-18 07:01:07 +00:00
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Ecava IntegraXor SQL injection"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "95907",
"refsource": "BID",
"url": "http://www.securityfocus.com/bid/95907"
},
{
"name": "https://ics-cert.us-cert.gov/advisories/ICSA-17-031-02",
"refsource": "MISC",
"url": "https://ics-cert.us-cert.gov/advisories/ICSA-17-031-02"
}
]
}
}