CVE-2013-5694 Information

Description

SQL injection vulnerability in status/service/acknowledge in Opsview before 4.4.1 allows remote attackers to execute arbitrary SQL commands via the service_selection parameter.

Reference

http://archives.neohapsis.com/archives/bugtraq/2013-10/0149.html http://docs.opsview.com/doku.php?id=opsview4.4:changesfixes http://osvdb.org/99038 http://osvdb.org/ref/99/opsview-sqli.txt http://packetstormsecurity.com/files/123821/Ops-View-Pre-4.4.1-Blind-SQL-Injection.html http://www.exploit-db.com/exploits/29326 http://www.securityfocus.com/bid/63387

Share on: