CVE-2014-1645: SQL Injection
SQL injection vulnerability in forcepasswd.do in the management GUI in Symantec LiveUpdate Administrator (LUA) 2.x before 2.3.2.110 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Symantec LiveUpdate Administrator (LUA)to a version that resolves this vulnerability.Fixed in 2.3.2.110
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1645?
CVE-2014-1645 has a high severity rating due to the potential for remote attackers to execute arbitrary SQL commands.
How do I fix CVE-2014-1645?
To fix CVE-2014-1645, upgrade Symantec LiveUpdate Administrator to version 2.3.2.110 or later.
What systems are affected by CVE-2014-1645?
CVE-2014-1645 affects Symantec LiveUpdate Administrator versions 2.x prior to 2.3.2.110.
What kind of vulnerability is CVE-2014-1645?
CVE-2014-1645 is classified as an SQL injection vulnerability.
Can I exploit CVE-2014-1645 remotely?
Yes, CVE-2014-1645 can be exploited remotely by attackers to execute SQL commands.