CVE-2014-0821: SQL Injection
SQL injection vulnerability in the download feature in Cybozu Garoon 2.x through 2.5.4 and 3.x through 3.7 SP3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2013-6930 and CVE-2013-6931.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0821?
CVE-2014-0821 has a severity rating that indicates it can be exploited by remote authenticated users to execute arbitrary SQL commands.
How do I fix CVE-2014-0821?
To fix CVE-2014-0821, upgrade Cybozu Garoon to a version that is not affected by this vulnerability, as specified in the vendor's security updates.
What versions of Cybozu Garoon are affected by CVE-2014-0821?
CVE-2014-0821 affects Cybozu Garoon versions 2.x through 2.5.4 and 3.x through 3.7 SP3.
Who can exploit CVE-2014-0821?
CVE-2014-0821 can be exploited by remote authenticated users of Cybozu Garoon.
What is SQL injection in the context of CVE-2014-0821?
SQL injection in the context of CVE-2014-0821 refers to the ability of an attacker to send malicious SQL queries through the download feature of Cybozu Garoon.