First published: Sun Feb 24 2013(Updated: )
SQL injection vulnerability in BigAntSoft BigAnt IM Message Server allows remote attackers to execute arbitrary SQL commands via an SHU (aka search user) request.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
BigAntSoft BigAnt IM Message Server |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-6273 is considered a critical vulnerability due to its potential for remote SQL injection attacks.
To fix CVE-2012-6273, it is recommended to upgrade to the latest version of BigAnt IM Message Server provided by BigAntSoft.
CVE-2012-6273 can be exploited to perform unauthorized SQL commands, potentially leading to data exfiltration or database compromise.
Yes, CVE-2012-6273 can be easily exploited by attackers with knowledge of SQL injection techniques, particularly through unauthenticated requests.
CVE-2012-6273 affects all versions of BigAnt IM Message Server prior to the vendor's response and resolution.