Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown
The Sungard eTRAKiT3 software version 3.2.1.17 may be vulnerable to SQL injecti…
Disclosure Date: July 13, 2018 (last updated November 27, 2024)
The valueAsString parameter inside the JSON payload contained by the ucLogin_txtLoginId_ClientStat POST parameter of the Sungard eTRAKiT3 software version 3.2.1.17 is not properly validated. An unauthenticated remote attacker may be able to modify the POST request and insert a SQL query which may then be executed by the backend server. eTRAKiT 3.2.1.17 was tested, but other versions may also be vulnerable.
0
Attacker Value
Unknown
CVE-2009-4930
Disclosure Date: July 12, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the twbkwbis.P_SecurityQuestion (aka Change Security Question) page in SunGard Banner Student System 7.4 allows remote attackers to inject arbitrary web script or HTML via the New Question field.
0
Attacker Value
Unknown
CVE-2008-4727
Disclosure Date: October 24, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the contact update page (ss/bwgkoemr.P_UpdateEmrgContacts) in SunGard Banner Student 7.3 allows remote attackers to inject arbitrary web script or HTML via the addr1 parameter. NOTE: this might be resultant from a CSRF vulnerability, but there are insufficient details to be sure.
0