CVE-2014-4873: SQL Injection
SQL injection vulnerability in TrackItWeb/Grid/GetData in BMC Track-It! 11.3.0.355 allows remote authenticated users to execute arbitrary SQL commands via crafted POST data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4873?
CVE-2014-4873 is classified as a medium severity vulnerability due to its potential for SQL injection exploitation.
How do I fix CVE-2014-4873?
To fix CVE-2014-4873, update BMC Track-It! to version 11.3.0.355 or a later patched version that mitigates the SQL injection vulnerability.
Who is affected by CVE-2014-4873?
CVE-2014-4873 affects BMC Track-It! version 11.3.0.355 and allows remote authenticated users to execute arbitrary SQL commands.
What type of vulnerability is CVE-2014-4873?
CVE-2014-4873 is an SQL injection vulnerability that allows unauthorized execution of SQL commands through crafted POST data.
Can CVE-2014-4873 be exploited remotely?
Yes, CVE-2014-4873 can be exploited remotely by authenticated users with the right POST data crafted to manipulate SQL queries.