Back to search
CVE-2012-5861
Published: Nov 23, 2012
Modified: Jul 8, 2025
PUBLISHED
Description
These Sinapsi devices do not check the validity of the data before executing queries. By accessing the SQL table of certain pages that do not require authentication within the device, attackers can leak information from the device. This could allow the attacker to compromise confidentiality.
| Vendor | Product | Versions |
|---|---|---|
Sinapsi | eSolar | affected 0 - < 2.0.2870_xxx_2.2.12 |
Sinapsi | eSolar DUO | affected 0 - < 2.0.2870_xxx_2.2.12 |
Sinapsi | eSolar Light | affected 0 - < 2.0.2870_xxx_2.2.12 |
Weaknesses (CWE)
References
21273
exploit
x_refsource_EXPLOIT-DB
20120911 Multiple vulnerabilities in Ezylog photovoltaic management server
mailing-list
x_refsource_BUGTRAQ
sinapsi-default-password(80200)
vdb-entry
x_refsource_XF
http://www.sinapsitech.it/default.asp?active_page_id=78&news_id=88
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now