CVE-2013-4945: SQL Injection
Multiple SQL injection vulnerabilities in BMC Service Desk Express (SDE) 10.2.1.95 allow remote attackers to execute arbitrary SQL commands via the (1) ASPSESSIONIDASSRATTQ, (2) TABLEWIDGET1, (3) TABLEWIDGET2, (4) browserDateTimeInfo, or (5) browserNumberInfo cookie parameter to DashBoardGUI.aspx; or the (6) UID parameter to login.aspx.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4945?
CVE-2013-4945 is classified as a high severity vulnerability due to the risk of remote SQL injection attacks.
How do I fix CVE-2013-4945?
To mitigate CVE-2013-4945, it is recommended to update BMC Service Desk Express to the latest version that addresses these SQL injection vulnerabilities.
What are the potential impacts of CVE-2013-4945?
Exploitation of CVE-2013-4945 can allow attackers to execute arbitrary SQL commands, potentially compromising the database and sensitive information.
Which versions of BMC Service Desk Express are affected by CVE-2013-4945?
CVE-2013-4945 affects BMC Service Desk Express version 10.2.1.95.
What kind of attack can be performed through CVE-2013-4945?
CVE-2013-4945 allows remote attackers to perform SQL injection attacks via specific cookie parameters.