Описание
SQL injection vulnerability in the LiveData service in CSWorks before 2.5.5233.0 allows remote attackers to execute arbitrary SQL commands via vectors related to pathnames contained in web API requests.
SQL injection vulnerability in the LiveData service in CSWorks before 2.5.5233.0 allows remote attackers to execute arbitrary SQL commands via vectors related to pathnames contained in web API requests.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2014-2351
- https://www.cisa.gov/news-events/ics-advisories/icsa-14-135-01
- http://ics-cert.us-cert.gov/advisories/ICSA-14-135-01
- http://www.controlsystemworks.com/blogengine/post/2014/05/08/Important-CSWorks-security-release-2552330
- http://www.securityfocus.com/bid/67427
Связанные уязвимости
nvd
больше 11 лет назад
SQL injection vulnerability in the LiveData service in CSWorks before 2.5.5233.0 allows remote attackers to execute arbitrary SQL commands via vectors related to pathnames contained in web API requests.