vendor:
Fiery Webtools
by:
Bernardo Trigo
8.8
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Fiery Webtools
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: None
CPE: a:xerox:fiery_webtools
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Unknown
2020
SQL Injection in Xerox Fiery Webtools
The vulnerability exists in /wt3/summary.php?select= if an attacker adds ' to the end of the URL, they can inject SQL code.
Mitigation:
The vendor should be contacted to patch the vulnerability.