CVE-2013-3578: Wave Embassy Remote Administration Server
High severity, CVSS 9.0. EPSS: 2.5% chance of exploitation in the next 30 days.
SQL injection vulnerability in the Help Desk application in Wave EMBASSY Remote Administration Server (ERAS) allows remote authenticated users to execute arbitrary SQL commands via the ct100$4MainController$TextBoxSearchValue parameter (aka the search field), leading to execution of operating-system commands.
Affected products
- Wave Embassy Remote Administration Server: affected versions not specified
- Wave Embassy Remote Administration Server Help Desk: affected versions not specified
Published 2013-07-15. Last modified 2026-06-16.