CVE-2013-4887: SQL Injection
Published Jan 29, 2014
·Updated
SQL injection vulnerability in index.php in Digital Signage Xibo 1.4.2 allows remote attackers to execute arbitrary SQL commands via the displayid parameter.
Affected Software
2 affected components
Springsignage Xibo=1.4.2
Xibosignage Xibo=1.4.2
Event History
Jan 29, 2014
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
via NVD·06:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-4887?
The severity of CVE-2013-4887 is considered high due to the potential for remote attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2013-4887?
You can fix CVE-2013-4887 by upgrading Digital Signage Xibo to the latest version that addresses this vulnerability.
3
What does CVE-2013-4887 affect?
CVE-2013-4887 affects Digital Signage Xibo version 1.4.2 specifically.
4
How does CVE-2013-4887 impact my system?
CVE-2013-4887 can allow attackers to manipulate your database, potentially leading to data loss or unauthorized access.
5
Is CVE-2013-4887 an SQL injection vulnerability?
Yes, CVE-2013-4887 is an SQL injection vulnerability that allows execution of arbitrary SQL commands via the displayid parameter.