« Volver al listado

CVE-2011-1562

Estado: ModificadaAlta (7.5)—

Ecava IntegraXor HMI before n 3.60 (Build 4032) allows remote attackers to bypass authentication and execute arbitrary SQL statements via unspecified vectors related to a crafted POST request. NOTE: some sources have reported this issue as SQL injection, but this might not be accurate.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2011-1562",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2011-04-05T15:19:35.587",
  "references": [
    {
      "url": "http://secunia.com/advisories/44105",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://twitter.com/#%21/djrbliss/status/50685527749431296",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.integraxor.com/blog/security-issue-20101222-0700-vulnerability-note",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.integraxor.com/blog/security-issue-sql-unauthenticated-vulnerability-note",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/47019",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.us-cert.gov/control_systems/pdf/ICSA-11-082-01.pdf",
      "tags": [
        "Patch",
        "US Government Resource"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2011/0761",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/66306",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/44105",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://twitter.com/#%21/djrbliss/status/50685527749431296",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.integraxor.com/blog/security-issue-20101222-0700-vulnerability-note",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.integraxor.com/blog/security-issue-sql-unauthenticated-vulnerability-note",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/47019",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.us-cert.gov/control_systems/pdf/ICSA-11-082-01.pdf",
      "tags": [
        "Patch",
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2011/0761",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/66306",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-89"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Ecava IntegraXor HMI before n 3.60 (Build 4032) allows remote attackers to bypass authentication and execute arbitrary SQL statements via unspecified vectors related to a crafted POST request. NOTE: some sources have reported this issue as SQL injection, but this might not be accurate."
    },
    {
      "lang": "es",
      "value": "Ecava IntegraXor HMI antes de v3.60 (Build 4032) permite a atacantes remotos evitar la autenticación y ejecutar comandos SQL a través de vectores no especificados relacionados con una solicitud POST manipulada. NOTA: algunas fuentes han informado de este problema como la inyección SQL, pero esto podría no ser exacta."
    }
  ],
  "lastModified": "2026-06-16T23:29:37.963",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ecava:integraxor:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4B12B7DF-7978-4188-9F07-9AA8A345911E",
              "versionEndIncluding": "3.60"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}