Multiple SQL injection vulnerabilities on the Sinapsi eSolar Light Photovoltaic System Monitor (aka Schneider Electric Ezylog photovoltaic SCADA management server), Sinapsi eSolar, and Sinapsi eSolar DUO with firmware prior to 2.0.2870_2.2.12 allow remote malicious users to execute arbitrary SQL commands via (1) the inverterselect parameter in a primo action to dettagliinverter.php or (2) the lingua parameter to changelanguagesession.php.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
sinapsitech sinapsi_firmware |
||
sinapsitech esolar_light_photovoltaic_system_monitor - |
||
sinapsitech esolar_duo_photovoltaic_system_monitor - |
||
sinapsitech esolar_photovoltaic_system_monitor - |