|
|||
Rule General Information |
---|
Release Date: | 2015-04-17 | |
Rule Name: | SQL Injection Attempt Using CREATE -3 Vulnerability (CVE-2014-7864) | |
Severity: | ||
CVE ID: | ||
Rule Protection Details |
---|
Description: | SQL injection is a vulnerability that allows an attacker to alter backend SQL statements by manipulating the user input. An SQL injection occurs when web applications accept user input that is directly placed into a SQL statement and doesn't properly filter out dangerous characters. | |
Impact: | An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully. | |
Affected OS: | Windows, Solaris, Other Unix, FreeBSD, Linux | |
Reference: | http://packetstormsecurity.com/files/130162/ManageEngine-File-Download-Content-Disclosure-SQL-Injection.html http://seclists.org/fulldisclosure/2015/Jan/114 http://www.securityfocus.com/archive/1/archive/1/534575/100/0/threaded |
|
Solutions |
---|
The vendor has updated advisory on its official website. Please check it for more information. |