CVE-2013-0684: SQL Injection
SQL injection vulnerability in Invensys Wonderware Information Server (WIS) 4.0 SP1SP1, 4.5- Portal, and 5.0- Portal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0684?
CVE-2013-0684 is classified as a critical vulnerability due to its potential to allow remote attackers to execute arbitrary SQL commands.
How do I fix CVE-2013-0684?
To mitigate CVE-2013-0684, upgrade to the latest version of Invensys Wonderware Information Server that addresses this vulnerability.
What versions of Invensys Wonderware Information Server are affected by CVE-2013-0684?
CVE-2013-0684 affects Invensys Wonderware Information Server versions 4.0 SP1SP1, 4.5 Portal, and 5.0 Portal.
Can CVE-2013-0684 be exploited remotely?
Yes, CVE-2013-0684 can be exploited remotely, allowing attackers to execute SQL commands over the network.
What type of vulnerability is CVE-2013-0684?
CVE-2013-0684 is an SQL injection vulnerability that allows unauthorized SQL command execution.