CVE-2013-2045: SQL Injection
Published Mar 7, 2014
·Updated
SQL injection vulnerability in lib/db.php in ownCloud Server 5.0.x before 5.0.6 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
Affected Software
12 affected components
ownCloud ownCloud=5.0.0
ownCloud ownCloud=5.0.1
ownCloud ownCloud=5.0.2
ownCloud ownCloud=5.0.3
ownCloud ownCloud=5.0.4
ownCloud ownCloud=5.0.5
ownCloud ownCloud Server=5.0.0
ownCloud ownCloud Server=5.0.1
ownCloud ownCloud Server=5.0.2
ownCloud ownCloud Server=5.0.3
ownCloud ownCloud Server=5.0.4
ownCloud ownCloud Server=5.0.5
Event History
Mar 7, 2014
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Mar 9, 2014
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-2045?
CVE-2013-2045 is classified as a medium severity SQL injection vulnerability.
2
How do I fix CVE-2013-2045?
To fix CVE-2013-2045, upgrade ownCloud Server to version 5.0.6 or later.
3
Who is affected by CVE-2013-2045?
CVE-2013-2045 affects remote authenticated users of ownCloud Server versions 5.0.0 to 5.0.5.
4
What does CVE-2013-2045 allow attackers to do?
CVE-2013-2045 allows remote authenticated users to execute arbitrary SQL commands.
5
Which software versions are impacted by CVE-2013-2045?
CVE-2013-2045 impacts ownCloud Server versions 5.0.0 through 5.0.5.