CVE-2012-1063: SQL Injection
Multiple SQL injection vulnerabilities in ManageEngine Applications Manager 9.x and 10.x allow remote attackers to execute arbitrary SQL commands via the (1) viewId parameter to fault/AlarmView.do or (2) period parameter to showHistoryData.do.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1063?
CVE-2012-1063 is classified as a high severity SQL injection vulnerability, allowing remote execution of arbitrary SQL commands.
How do I fix CVE-2012-1063?
To mitigate CVE-2012-1063, users should upgrade to a patched version of ManageEngine Applications Manager that addresses the SQL injection vulnerabilities.
What software versions are affected by CVE-2012-1063?
CVE-2012-1063 affects ManageEngine Applications Manager versions 9.1 through 10.3.
Can CVE-2012-1063 lead to data exposure?
Yes, CVE-2012-1063 can potentially lead to unauthorized data exposure due to arbitrary SQL command execution.
Is CVE-2012-1063 exploitable remotely?
Yes, CVE-2012-1063 can be exploited remotely, allowing attackers to conduct SQL injection attacks without local access.