CVE-2014-1650: SQL Injection
Published Jun 18, 2014
·Updated
SQL injection vulnerability in user.php in the management console in Symantec Web Gateway (SWG) before 5.2.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
Affected Software
1 affected component
Symantec Web Gateway<=5.2
Event History
Jun 18, 2014
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-1650?
CVE-2014-1650 is classified as a medium severity vulnerability due to the potential for SQL injection by authenticated users.
2
How do I fix CVE-2014-1650?
To mitigate CVE-2014-1650, upgrade Symantec Web Gateway to version 5.2.1 or later.
3
Who is affected by CVE-2014-1650?
CVE-2014-1650 affects all versions of Symantec Web Gateway prior to 5.2.1.
4
What type of vulnerability is CVE-2014-1650?
CVE-2014-1650 is an SQL injection vulnerability that allows execution of arbitrary SQL commands.
5
Can CVE-2014-1650 be exploited remotely?
Yes, CVE-2014-1650 can be exploited remotely by authenticated users.