CVE-2012-5861
23.11.2012, 12:09
Multiple SQL injection vulnerabilities on the Sinapsi eSolar Light Photovoltaic System Monitor (aka Schneider Electric Ezylog photovoltaic SCADA management server), Sinapsi eSolar, and Sinapsi eSolar DUO with firmware before 2.0.2870_2.2.12 allow remote attackers to execute arbitrary SQL commands via (1) the inverterselect parameter in a primo action to dettagliinverter.php or (2) the lingua parameter to changelanguagesession.php.
Vendor | Product | Version |
---|---|---|
sinapsitech | sinapsi_firmware | 𝑥 ≤ 2.0.2870 |
sinapsitech | esolar_duo_photovoltaic_system_monitor | - |
sinapsitech | esolar_light_photovoltaic_system_monitor | - |
sinapsitech | esolar_photovoltaic_system_monitor | - |
𝑥
= Vulnerable software versions
References