First published: Sat Dec 28 2013(Updated: )
SQL injection vulnerability in Cybozu Garoon 3.7 SP2 and earlier allows remote authenticated users to execute arbitrary SQL commands via crafted API input.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Cybozu Garoon | <=3.7 | |
Cybozu Garoon | =3.7 | |
Cybozu Garoon | =3.7-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2013-6929 is classified as high due to the potential for remote authenticated users to execute arbitrary SQL commands.
To fix CVE-2013-6929, upgrade to the latest version of Cybozu Garoon that addresses this SQL injection vulnerability.
CVE-2013-6929 affects remote authenticated users of Cybozu Garoon version 3.7 SP2 and earlier.
CVE-2013-6929 is an SQL injection vulnerability that allows the execution of arbitrary SQL commands.
The potential impacts of CVE-2013-6929 include unauthorized access to data and manipulation of the database by attackers.