SBA Security Advisory – RXTEC RXAdmin – SQL Injection Vulnerability (CVE-2015-8298)
Vulnerability Overview
SQL injection vulnerability in the RXTEC RXAdmin Login Page allows remote attackers to execute arbitrary SQL commands via several HTTP parameter.
- Type of Vulnerability: SQL injection
- CVE ID: CVE-2015-8298
- Impact: Critical
Links
Credits
- Thomas Konrad (SBA Research)