CVE-2013-6001: SQL Injection
Published Dec 5, 2013
·Updated
SQL injection vulnerability in the Space function in Cybozu Garoon before 3.7 SP1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
Affected Software
30 affected components
Cybozu Garoon<=3.7
Cybozu Garoon=2.0-sp1
Cybozu Garoon=2.0-sp2
Cybozu Garoon=2.0-sp3
Cybozu Garoon=2.0-sp4
Cybozu Garoon=2.0-sp5
Cybozu Garoon=2.0-sp6
Cybozu Garoon=2.1
Cybozu Garoon=2.1-sp1
Cybozu Garoon=2.1-sp2
Cybozu Garoon=2.1-sp3
Cybozu Garoon=2.5
Cybozu Garoon=2.5-sp1
Cybozu Garoon=2.5-sp2
Cybozu Garoon=2.5-sp3
Cybozu Garoon=2.5-sp4
Cybozu Garoon=3.0
Cybozu Garoon=3.0-sp1
Cybozu Garoon=3.0-sp2
Cybozu Garoon=3.0-sp3
Cybozu Garoon=3.1
Cybozu Garoon=3.1-sp1
Cybozu Garoon=3.1-sp2
Cybozu Garoon=3.1-sp3
Cybozu Garoon=3.5
Cybozu Garoon=3.5-sp1
Cybozu Garoon=3.5-sp2
Cybozu Garoon=3.5-sp3
Cybozu Garoon=3.5-sp4
Cybozu Garoon=3.5-sp5
Event History
Dec 5, 2013
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-6001?
CVE-2013-6001 is classified as a medium severity SQL injection vulnerability.
2
How do I fix CVE-2013-6001?
To fix CVE-2013-6001, update your Cybozu Garoon installation to version 3.7 SP1 or later.
3
Who is affected by CVE-2013-6001?
CVE-2013-6001 affects remote authenticated users of Cybozu Garoon versions before 3.7 SP1.
4
What kind of attacks can CVE-2013-6001 facilitate?
CVE-2013-6001 can facilitate arbitrary SQL command execution by authenticated users.
5
Is it necessary to apply patches for CVE-2013-6001 immediately?
Yes, applying patches for CVE-2013-6001 is essential to prevent potential exploitation.