The Sungard eTRAKiT3 software version 3.2.1.17 may be vulnerable to SQL injection which may allow a remote unauthenticated attacker to run a subset of SQL commands against the back-end database
28Vexday Risk Score
Sin señal de explotación. Ella tiene prueba de concepto pública.
ssvc Attendepss 12%
de la publicación al arma0 días
Publicada en NVD13 jul
1ª PoC2 jun
probabilidad de explotación
12%top 4% de las CVE
explotación observada
noninguna fuente lo reporta
1 exploit(s) público(s)
The valueAsString parameter inside the JSON payload contained by the ucLogin_txtLoginId_ClientStat POST parameter of the Sungard eTRAKiT3 software version 3.2.1.17 is not properly validated. An unauthenticated remote attacker may be able to modify the POST request and insert a SQL query which may then be executed by the backend server. eTRAKiT 3.2.1.17 was tested, but other versions may also be vulnerable.
Productos afectados
Sungard · eTRAKiT3PoCs públicas encontradas — 1
exploitdbwww.exploit-db.com/exploits/42111no verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.