← Vulnerability feed

Vulnerability record · CVE-2017-6050 · published 21 June 2017

CVE-2017-6050: Ecava integraxor sql injection vulnerability

Ecava · Integraxor

A SQL Injection issue was discovered in Ecava IntegraXor Versions 5.2.1231.0 and prior. The application fails to properly validate user input, which may allow for an unauthenticated attacker to remotely execute arbitrary code in the form of SQL queries.

9.8 CVSS 3.0 Critical EPSS 3.5% · top 11.2% CWE-89 · SQL injection
9.8CVSS 3.0 base score, v2 7.5
3.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

A SQL Injection issue was discovered in Ecava IntegraXor Versions 5.2.1231.0 and prior. The application fails to properly validate user input, which may allow for an unauthenticated attacker to remotely execute arbitrary code in the form of SQL queries.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-6050 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2010-4597Ecava integraxor memory buffer overflow vulnerabilityStack-based buffer overflow in the save method in the IntegraXor.Project ActiveX control in igcomm.dll in Ecava IntegraXor Human-Machine Interface (H…EPSS 19%9.8CVE-2016-8341Ecava integraxor sql injection vulnerabilityAn issue was discovered in Ecava IntegraXor Version 5.0.413.0. The Ecava IntegraXor web server has parameters that are vulnerable to SQL injection. I…EPSS 1.7%9.3CVE-2012-4700Ecava integraxor memory buffer overflow vulnerabilityMultiple buffer overflows in an ActiveX control in PE3DO32A.ocx in IntegraXor SCADA Server 4.00 build 4250.0 and earlier allow remote attackers to ex…EPSS 3.8%9.3CVE-2012-0246Ecava integraxor path traversal vulnerabilityDirectory traversal vulnerability in an unspecified ActiveX control in Ecava IntegraXor before 3.71.4200 allows remote attackers to execute arbitrary…EPSS 5.9%8.3CVE-2014-2375Ecava integraxor permissions and access controls vulnerabilityEcava IntegraXor SCADA Server Stable 4.1.4360 and earlier and Beta 4.1.4392 and earlier allows remote attackers to read or write to arbitrary files, …EPSS 2.3%7.8CVE-2014-0753Ecava integraxor stack-based buffer overflow vulnerabilityStack-based buffer overflow in the SCADA server in Ecava IntegraXor before 4.1.4390 allows remote attackers to cause a denial of service (system cras…EPSS 2.5%7.5CVE-2016-2306Ecava integraxor vulnerabilityThe HMI web server in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to obtain sensitive cleartext information by sniffing the networ…EPSS 1.9%7.5CVE-2014-2376Ecava integraxor sql injection vulnerabilitySQL injection vulnerability in Ecava IntegraXor SCADA Server Stable 4.1.4360 and earlier and Beta 4.1.4392 and earlier allows remote attackers to exe…EPSS 2.0%

Source: NIST National Vulnerability Database (record CVE-2017-6050), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.