SQL injection vulnerability in the LiveData service in CSWorks before 2.5.5233.0 allows remote attackers to execute arbitrary SQL commands via vectors related to pathnames contained in web API requests.
References
Link | Resource |
---|---|
http://ics-cert.us-cert.gov/advisories/ICSA-14-135-01 | US Government Resource |
http://www.controlsystemworks.com/blogengine/post/2014/05/08/Important-CSWorks-security-release-2552330 | Vendor Advisory |
http://www.securityfocus.com/bid/67427 |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: icscert
Published: 2014-05-20T10:00:00
Updated: 2015-05-12T18:57:00
Reserved: 2014-03-13T00:00:00
Link: CVE-2014-2351
JSON object: View
NVD Information
Status : Analyzed
Published: 2014-05-20T11:13:37.873
Modified: 2015-10-08T14:47:15.180
Link: CVE-2014-2351
JSON object: View
Redhat Information
No data.
CWE