First published: Thu Jul 03 2014(Updated: )
Multiple SQL injection vulnerabilities in Kerio Control Statistics in Kerio Control (formerly WinRoute Firewall) before 8.3.2 allow remote authenticated users to execute arbitrary SQL commands via the (1) x_16 or (2) x_17 parameter to print.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GFI Software KerioControl | <=8.3.1 | |
GFI Software KerioControl | =8.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3857 is classified as a high severity vulnerability due to its potential for remote authenticated users to execute arbitrary SQL commands.
To fix CVE-2014-3857, upgrade Kerio Control to version 8.3.2 or later.
CVE-2014-3857 affects users of Kerio Control versions 8.3.1 and earlier.
The attack vectors for CVE-2014-3857 involve remote authenticated users exploiting SQL injection vulnerabilities in the print.php file.
CVE-2014-3857 specifically targets the Kerio Control Statistics feature through the x_16 and x_17 parameters.