CVE-2013-5028: SQL Injection
Published Oct 11, 2013
·Updated
SQL injection vulnerability in IT/hardware-list.dll in Kwoksys Kwok Information Server before 2.8.5 allows remote authenticated users to execute arbitrary SQL commands via the (1) hardwareType, (2) hardwareStatus, or (3) hardwareLocation parameter in a search command.
Affected Software
2 affected components
Kwoksys Information Server<=2.8.4
Kwoksys Information Server=2.8.3
Event History
Oct 11, 2013
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-5028?
CVE-2013-5028 is considered a high severity SQL injection vulnerability.
2
How do I fix CVE-2013-5028?
To fix CVE-2013-5028, upgrade to Kwok Information Server version 2.8.5 or later.
3
Who is affected by CVE-2013-5028?
CVE-2013-5028 affects remote authenticated users of Kwok Information Server versions prior to 2.8.5.
4
What types of attacks are possible with CVE-2013-5028?
CVE-2013-5028 allows attackers to execute arbitrary SQL commands through manipulated parameters.
5
In which component does CVE-2013-5028 exist?
CVE-2013-5028 exists in the IT/hardware-list.dll component of Kwok Information Server.