CVE-2012-0226: SQL Injection
Published Apr 2, 2012
·Updated
SQL injection vulnerability in Invensys Wonderware Information Server 4.0 SP1 and 4.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Affected Software
2 affected components
Invensys Wonderware Information Server=4.0-sp1
Invensys Wonderware Information Server=4.5
Event History
Apr 2, 2012
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-0226?
CVE-2012-0226 is classified as a high severity vulnerability due to its potential for remote SQL execution.
2
How do I fix CVE-2012-0226?
To fix CVE-2012-0226, update Invensys Wonderware Information Server to the latest patched version.
3
What software is affected by CVE-2012-0226?
CVE-2012-0226 affects Invensys Wonderware Information Server versions 4.0 SP1 and 4.5.
4
What type of attack does CVE-2012-0226 allow?
CVE-2012-0226 allows remote attackers to execute arbitrary SQL commands.
5
What are the potential impacts of CVE-2012-0226?
The potential impacts of CVE-2012-0226 include data loss, unauthorized access, and manipulation of the database.