VendorsWaveembassy_remote_administration_server_help_deskall versions
Vulnerabilities

Wave EMBASSY Remote Administration Server (ERAS) Help Desk Application

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2013-3578
SQL injection vulnerability in the Help Desk application in Wave EMBASSY Remote Administration Server (ERAS) allows remote authenticated users to execute arbitrary SQL commands via the ct100$4MainController$TextBoxSearchValue parameter (aka the search field), leading to execution of operating-system commands.
Published 2013-07-15 · Modified
9.0EPSS 0.025
CVE-2013-3577
SQL injection vulnerability in the Help Desk application in Wave EMBASSY Remote Administration Server (ERAS) allows remote attackers to execute arbitrary SQL commands via the ct100$4MainController$TextBoxSearchValue parameter (aka the search field).
Published 2013-07-15 · Modified
7.5EPSS 0.013