CVE-2014-1651: SQL Injection
Published Jun 18, 2014
·Updated
SQL injection vulnerability in clientreport.php in the management console in Symantec Web Gateway (SWG) before 5.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Affected Software
2 affected components
Symantec Web Gateway<=5.1.1
Symantec Web Gateway=5.1
Event History
Jun 18, 2014
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-1651?
CVE-2014-1651 is considered to have a high severity due to its ability to allow remote attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2014-1651?
To fix CVE-2014-1651, upgrade Symantec Web Gateway to version 5.2 or later.
3
What are the risks associated with CVE-2014-1651?
The risks associated with CVE-2014-1651 include potential data breaches and unauthorized access to sensitive database information.
4
Who is affected by CVE-2014-1651?
CVE-2014-1651 affects all versions of Symantec Web Gateway prior to version 5.2.
5
What type of vulnerability is CVE-2014-1651?
CVE-2014-1651 is categorized as an SQL injection vulnerability.