CVE-2012-1234: SQL Injection
SQL injection vulnerability in Advantech/BroadWin WebAccess 7.0 allows remote authenticated users to execute arbitrary SQL commands via a malformed URL. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0234.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1234?
CVE-2012-1234 is considered to be of moderate severity due to its potential for SQL injection leading to unauthorized data access.
How do I fix CVE-2012-1234?
To fix CVE-2012-1234, ensure that you update Advantech WebAccess to a version beyond 7.0 that addresses this SQL injection vulnerability.
Who is affected by CVE-2012-1234?
Users of Advantech WebAccess versions 5.0 and up to 6.0 are affected by CVE-2012-1234.
What type of vulnerability is CVE-2012-1234?
CVE-2012-1234 is an SQL injection vulnerability that allows remote authenticated users to execute arbitrary SQL commands.
What are the potential impacts of CVE-2012-1234?
The potential impacts of CVE-2012-1234 include unauthorized access to the database, data manipulation, and possible data loss.