CVE-2012-6427

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
23/12/2012
Last modified:
01/07/2025

Description

The Carlo Gavazzi <br /> EOS-Box<br /> <br /> does not check the validity of the data before executing queries. By accessing the SQL table of certain pages that do not require authentication, attackers can leak information from the device. This could allow the attacker to compromise confidentiality.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:carlosgavazzi:eos-box_photovoltaic_monitoring_system_firmware:*:*:*:*:*:*:*:* 1.0.0 (including)
cpe:2.3:h:carlosgavazzi:eos-box_photovoltaic_monitoring_system:-:*:*:*:*:*:*:*