7.5
CVSSv2

CVE-2012-5861

Published: 23/11/2012 Updated: 29/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities on the Sinapsi eSolar Light Photovoltaic System Monitor (aka Schneider Electric Ezylog photovoltaic SCADA management server), Sinapsi eSolar, and Sinapsi eSolar DUO with firmware prior to 2.0.2870_2.2.12 allow remote malicious users to execute arbitrary SQL commands via (1) the inverterselect parameter in a primo action to dettagliinverter.php or (2) the lingua parameter to changelanguagesession.php.

Vulnerable Product Search on Vulmon Subscribe to Product

sinapsitech sinapsi_firmware

sinapsitech esolar_light_photovoltaic_system_monitor -

sinapsitech esolar_duo_photovoltaic_system_monitor -

sinapsitech esolar_photovoltaic_system_monitor -

Exploits

Multiple vulnerabilities in Ezylog photovoltaic management server ================================================================= [ADVISORY INFORMATION] Title: Multiple vulnerabilities in Ezylog photovoltaic management server Discovery date: 27/08/2012 Release date: 11/09/2012 Credits: Roberto Paleari (roberto@greyhatsit, @rpa ...