SCADA Vulnerabilities & Exposures (SVE)

CRITIFENCE® SCADA Vulnerabilities and Exposures Database (SVE)

[SVE-977443138] ITS SCADA Username - SQL Injection Vulnerability

Date Type Platform Author EDB-ID CVE-ID OSVDB-ID Download App SIS Signature
2010-10-04HMIphpEugene Salov34798N/AN/AN/AN/A

Source

						
							
								
source: http://www.securityfocus.com/bid/43680/info

ITS SCADA is prone to an SQL-injection vulnerability.

Exploiting this issue can allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. 

User ID = 1' or 1=(select top 1 password from Users)--
Password = blank