Security Advisory
CVE-2012-3032
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
SQL injection vulnerability in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allows remote attackers to execute arbitrary SQL commands via a crafted SOAP message.