CVE-2012-0234: SQL Injection
Published Feb 21, 2012
·Updated
SQL injection vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary SQL commands via a malformed URL.
Affected Software
2 affected components
Advantech Advantech WebAccess<=6.0
Advantech Advantech WebAccess=5.0
Remediation
Event History
Feb 21, 2012
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-0234?
CVE-2012-0234 is considered a high-severity SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2012-0234?
To fix CVE-2012-0234, upgrade to Advantech WebAccess version 7.0 or later where the vulnerability has been patched.
3
What are the affected software versions of CVE-2012-0234?
CVE-2012-0234 affects Advantech WebAccess versions prior to 7.0, specifically versions 5.0 and below.
4
Can CVE-2012-0234 be exploited remotely?
Yes, CVE-2012-0234 can be exploited remotely by sending a malformed URL to the affected server.
5
What kind of attacks can be performed using CVE-2012-0234?
Exploitation of CVE-2012-0234 allows attackers to execute arbitrary SQL commands, potentially leading to data disclosure or corruption.