CVE-2013-4461: SQL Injection
A flaw was found in the way cumin parsed POST request data. A remote attacker could potentially use this flaw to perform SQL injection attacks on cumin's database.
Other sources
SQL injection vulnerability in the web interface for cumin in Red Hat Enterprise MRG Grid 2.4 allows remote attackers to execute arbitrary SQL commands via vectors related to the "filtering table operator."
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4461?
CVE-2013-4461 has been classified as a critical vulnerability due to its potential for remote SQL injection attacks.
How do I fix CVE-2013-4461?
To fix CVE-2013-4461, it is recommended to upgrade to the patched version of Red Hat Enterprise MRG that addresses the SQL injection flaw.
What type of attack is possible with CVE-2013-4461?
CVE-2013-4461 allows for remote SQL injection attacks that could compromise the integrity of cumin's database.
Which software is affected by CVE-2013-4461?
CVE-2013-4461 affects Red Hat Enterprise MRG Grid version 2.4.
Is CVE-2013-4461 exploitable without authentication?
Yes, CVE-2013-4461 is exploitable by remote attackers without the need for authentication.