First published: Mon Oct 20 2014(Updated: )
SQL injection vulnerability in dispatch.php in Achievo 1.4.5 allows remote authenticated users to execute arbitrary SQL commands via the activityid parameter in a stats action.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Achievo Achievo | =1.4.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-5865 is classified as a high severity vulnerability due to its potential to allow remote authenticated users to execute arbitrary SQL commands.
To fix CVE-2012-5865, you should upgrade Achievo to a later version that has addressed this SQL injection vulnerability.
Users of Achievo version 1.4.5 are affected by CVE-2012-5865 if they have remote authenticated access.
CVE-2012-5865 is an SQL injection vulnerability that allows attackers to manipulate database queries.
No, CVE-2012-5865 requires that an attacker is an authenticated user to exploit the vulnerability.