CVE-2014-3932: SQL Injection
Published Jun 2, 2014
·Updated
SQL injection vulnerability in the device registration component in wsf/webservice.php in CoSoSys Endpoint Protector 4 4.3.0.4 and 4.4.0.2 allows remote attackers to execute arbitrary SQL commands via unspecified parameters.
Affected Software
2 affected components
CoSoSys Endpoint Protector=4.3.0.4
CoSoSys Endpoint Protector=4.4.0.2
Event History
Jun 2, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-3932?
CVE-2014-3932 has a medium severity rating due to its potential for remote SQL injection attacks.
2
How do I fix CVE-2014-3932?
Updating CoSoSys Endpoint Protector to versions later than 4.4.0.2 resolves the vulnerability in CVE-2014-3932.
3
What types of attacks are possible with CVE-2014-3932?
CVE-2014-3932 allows remote attackers to execute arbitrary SQL commands on the affected systems.
4
Which versions of CoSoSys Endpoint Protector are affected by CVE-2014-3932?
CVE-2014-3932 affects CoSoSys Endpoint Protector versions 4.3.0.4 and 4.4.0.2.
5
Is CVE-2014-3932 being actively exploited?
There are reports suggesting that CVE-2014-3932 could be leveraged by attackers, indicating a risk of exploitation.