CVE-2005-1454: SQL Injection
SQL injection vulnerability in the radiusxlat function in the SQL module for FreeRADIUS 1.0.2 and earlier allows remote authenticated users to execute arbitrary SQL commands via (1) groupmembershipquery, (2) simulcountquery, or (3) simulverifyquery configuration entries.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-1454?
CVE-2005-1454 is considered a critical vulnerability due to its potential for remote authenticated users to execute arbitrary SQL commands.
How do I fix CVE-2005-1454?
To fix CVE-2005-1454, upgrade FreeRADIUS to version 1.0.3 or later, which addresses the SQL injection issues.
What systems are affected by CVE-2005-1454?
CVE-2005-1454 affects FreeRADIUS version 1.0.2 and earlier.
What types of SQL commands can be executed via CVE-2005-1454?
CVE-2005-1454 allows remote authenticated users to execute arbitrary SQL commands via group_membership_query, simul_count_query, or simul_verify_query configurations.
Is CVE-2005-1454 still relevant today?
While CVE-2005-1454 is an older vulnerability, it remains relevant for installations running affected versions of FreeRADIUS that haven't been updated.