CVE-2012-5865: SQL Injection
Published Oct 20, 2014
·Updated
SQL injection vulnerability in dispatch.php in Achievo 1.4.5 allows remote authenticated users to execute arbitrary SQL commands via the activityid parameter in a stats action.
Affected Software
1 affected component
Achievo Achievo=1.4.5
Event History
Oct 20, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-5865?
CVE-2012-5865 is classified as a high severity vulnerability due to its potential to allow remote authenticated users to execute arbitrary SQL commands.
2
How do I fix CVE-2012-5865?
To fix CVE-2012-5865, you should upgrade Achievo to a later version that has addressed this SQL injection vulnerability.
3
Who is affected by CVE-2012-5865?
Users of Achievo version 1.4.5 are affected by CVE-2012-5865 if they have remote authenticated access.
4
What type of vulnerability is CVE-2012-5865?
CVE-2012-5865 is an SQL injection vulnerability that allows attackers to manipulate database queries.
5
Can CVE-2012-5865 be exploited without authentication?
No, CVE-2012-5865 requires that an attacker is an authenticated user to exploit the vulnerability.