CVE-2013-5697: SQL Injection
Published Sep 30, 2013
·Updated
SQL injection vulnerability in modaccounting.c in the modaccounting module 0.5 and earlier for Apache allows remote attackers to execute arbitrary SQL commands via a Host header.
Affected Software
46 affected components
Simone Tellini Mod Accounting<=0.5
Apache HTTP Server=1.3
Apache HTTP Server=1.3.0
Apache HTTP Server=1.3.1
Apache HTTP Server=1.3.1.1
Apache HTTP Server=1.3.2
Apache HTTP Server=1.3.3
Apache HTTP Server=1.3.4
Apache HTTP Server=1.3.5
Apache HTTP Server=1.3.6
Apache HTTP Server=1.3.7
Apache HTTP Server=1.3.8
Apache HTTP Server=1.3.9
Apache HTTP Server=1.3.10
Apache HTTP Server=1.3.11
Apache HTTP Server=1.3.12
Apache HTTP Server=1.3.13
Apache HTTP Server=1.3.14
Apache HTTP Server=1.3.15
Apache HTTP Server=1.3.16
Apache HTTP Server=1.3.17
Apache HTTP Server=1.3.18
Apache HTTP Server=1.3.19
Apache HTTP Server=1.3.20
Apache HTTP Server=1.3.22
Apache HTTP Server=1.3.23
Apache HTTP Server=1.3.24
Apache HTTP Server=1.3.25
Apache HTTP Server=1.3.26
Apache HTTP Server=1.3.27
Apache HTTP Server=1.3.28
Apache HTTP Server=1.3.29
Apache HTTP Server=1.3.30
Apache HTTP Server=1.3.31
Apache HTTP Server=1.3.32
Apache HTTP Server=1.3.33
Apache HTTP Server=1.3.34
Apache HTTP Server=1.3.35
Apache HTTP Server=1.3.36
Apache HTTP Server=1.3.37
Apache HTTP Server=1.3.38
Apache HTTP Server=1.3.39
Apache HTTP Server=1.3.41
Apache HTTP Server=1.3.42
Apache HTTP Server=1.3.65
Apache HTTP Server=1.3.68
Event History
Sep 30, 2013
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-5697?
CVE-2013-5697 is considered a medium severity SQL injection vulnerability.
2
How do I fix CVE-2013-5697?
To fix CVE-2013-5697, upgrade the mod_accounting module to version 0.6 or later.
3
Which software versions are affected by CVE-2013-5697?
CVE-2013-5697 affects mod_accounting module versions 0.5 and earlier.
4
Can CVE-2013-5697 be exploited remotely?
Yes, CVE-2013-5697 can be exploited by remote attackers through crafted Host headers.
5
What type of vulnerability is CVE-2013-5697?
CVE-2013-5697 is an SQL injection vulnerability that allows arbitrary SQL commands execution.