Show filters
1 Total Results
Displaying 1-1 of 1
Sort by:
Attacker Value
Unknown

The Sungard eTRAKiT3 software version 3.2.1.17 may be vulnerable to SQL injecti…

Disclosure Date: July 13, 2018 (last updated November 27, 2024)
The valueAsString parameter inside the JSON payload contained by the ucLogin_txtLoginId_ClientStat POST parameter of the Sungard eTRAKiT3 software version 3.2.1.17 is not properly validated. An unauthenticated remote attacker may be able to modify the POST request and insert a SQL query which may then be executed by the backend server. eTRAKiT 3.2.1.17 was tested, but other versions may also be vulnerable.
0