CVE-2012-0244: SQL Injection
Published Feb 21, 2012
·Updated
Multiple SQL injection vulnerabilities in Advantech/BroadWin WebAccess before 7.0 allow remote attackers to execute arbitrary SQL commands via crafted string input.
Affected Software
2 affected components
Advantech Advantech WebAccess<=6.0
Advantech Advantech WebAccess=5.0
Remediation
Event History
Feb 21, 2012
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-0244?
CVE-2012-0244 is classified as a high severity vulnerability due to its potential for remote SQL injection attacks.
2
How do I fix CVE-2012-0244?
To fix CVE-2012-0244, upgrade Advantech/BroadWin WebAccess to version 7.0 or later where the vulnerabilities are patched.
3
What type of vulnerability is CVE-2012-0244?
CVE-2012-0244 is an SQL injection vulnerability that allows attackers to execute arbitrary SQL commands.
4
Can CVE-2012-0244 be exploited remotely?
Yes, CVE-2012-0244 can be exploited remotely by attackers through crafted string inputs.
5
Which versions of Advantech WebAccess are affected by CVE-2012-0244?
CVE-2012-0244 affects Advantech WebAccess versions prior to 7.0, including versions 5.0 and 6.0.