ID

VAR-201209-0660


TITLE

Ezylog photovoltaic management server Command injection vulnerability

Trust: 0.8

sources: IVD: 74a9f41c-1f56-11e6-abef-000c29c66e3d // CNVD: CNVD-2012-5079

DESCRIPTION

Ezylog photovoltaic management server is a SCADA product. The Ezylog photovoltaic management server \"ping.php\" script failed to properly filter the \"ip_dominio\" POST parameter, allowing an attacker to exploit the vulnerability to execute arbitrary commands with administrator privileges

Trust: 0.72

sources: CNVD: CNVD-2012-5079 // IVD: 74a9f41c-1f56-11e6-abef-000c29c66e3d

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: 74a9f41c-1f56-11e6-abef-000c29c66e3d // CNVD: CNVD-2012-5079

AFFECTED PRODUCTS

vendor:schneidermodel:electric ezylog photovoltaic management serverscope: - version: -

Trust: 0.6

vendor:schneidermodel:electric ezylog photovoltaic management server nullscope:eqversion:*

Trust: 0.2

sources: IVD: 74a9f41c-1f56-11e6-abef-000c29c66e3d // CNVD: CNVD-2012-5079

CVSS

SEVERITY

CVSSV2

CVSSV3

IVD: 74a9f41c-1f56-11e6-abef-000c29c66e3d
value: HIGH

Trust: 0.2

IVD: 74a9f41c-1f56-11e6-abef-000c29c66e3d
severity: NONE
baseScore: NONE
vectorString: NONE
accessVector: NONE
accessComplexity: NONE
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: UNKNOWN

Trust: 0.2

sources: IVD: 74a9f41c-1f56-11e6-abef-000c29c66e3d

TYPE

Command injection

Trust: 0.2

sources: IVD: 74a9f41c-1f56-11e6-abef-000c29c66e3d

EXTERNAL IDS

db:CNVDid:CNVD-2012-5079

Trust: 0.8

db:IVDid:74A9F41C-1F56-11E6-ABEF-000C29C66E3D

Trust: 0.2

sources: IVD: 74a9f41c-1f56-11e6-abef-000c29c66e3d // CNVD: CNVD-2012-5079

REFERENCES

url:http://seclists.org/bugtraq/2012/sep/44

Trust: 0.6

sources: CNVD: CNVD-2012-5079

SOURCES

db:IVDid:74a9f41c-1f56-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2012-5079

LAST UPDATE DATE

2022-05-17T01:51:14.349000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2012-5079date:2012-09-13T00:00:00

SOURCES RELEASE DATE

db:IVDid:74a9f41c-1f56-11e6-abef-000c29c66e3ddate:2012-09-13T00:00:00
db:CNVDid:CNVD-2012-5079date:2012-09-13T00:00:00