RULE(RULE ID:311631)

Rule General Information
Release Date: 2015-04-17
Rule Name: SQL Injection Attempt Using CREATE -3 Vulnerability (CVE-2014-7864)
Severity:
CVE ID:
Rule Protection Details
Description: SQL injection is a vulnerability that allows an attacker to alter backend SQL statements by manipulating the user input. An SQL injection occurs when web applications accept user input that is directly placed into a SQL statement and doesn't properly filter out dangerous characters.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Solaris, Other Unix, FreeBSD, Linux
Reference: http://packetstormsecurity.com/files/130162/ManageEngine-File-Download-Content-Disclosure-SQL-Injection.html
http://seclists.org/fulldisclosure/2015/Jan/114
http://www.securityfocus.com/archive/1/archive/1/534575/100/0/threaded
Solutions
The vendor has updated advisory on its official website. Please check it for more information.