CVE-2013-6930: SQL Injection
SQL injection vulnerability in the page-navigation implementation in Cybozu Garoon 2.0.0 through 2.0.6, 2.1.0 through 2.1.3, 2.5.0 through 2.5.4, 3.0.0 through 3.0.3, 3.5.0 through 3.5.5, and 3.7.x before 3.7.3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2013-6929.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6930?
CVE-2013-6930 has a medium severity rating, which allows authenticated users to execute arbitrary SQL commands.
How do I fix CVE-2013-6930?
To fix CVE-2013-6930, upgrade Cybozu Garoon to version 3.7.3 or later, which addresses the SQL injection vulnerability.
Who is affected by CVE-2013-6930?
CVE-2013-6930 affects specific versions of Cybozu Garoon, from 2.0.0 through 3.7.2.
What kind of vulnerability is CVE-2013-6930?
CVE-2013-6930 is an SQL injection vulnerability related to page navigation within the application.
Can CVE-2013-6930 be exploited remotely?
Yes, CVE-2013-6930 can be exploited remotely by authenticated users.