PatchSiren

Ecava CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Ecava CVE published 2017-02-13

CVE-2016-8341

CVE-2016-8341 is a critical SQL injection vulnerability affecting Ecava IntegraXor version 5.0.413.0. NVD classifies the issue as remotely exploitable with no privileges or user interaction required, and the weakness is mapped to CWE-89. Because the vulnerable web server parameters may allow database read, write, and delete operations when input is not sanitized, affected deployments should treat this as [truncated]