CVE-2014-5503: SQL Injection
Published Oct 7, 2014
·Updated
SQL injection vulnerability in the Guest Login Portal in the Sophos Cyberoam appliances with CyberoamOS before 10.6.1 GA allows remote attackers to execute arbitrary SQL commands via the addguestuser opcode.
Affected Software
2 affected components
Cyberoam Cyberoam Os<=10.4
Cyberoam Cyberoam Os<=10.6.1
Event History
Oct 7, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-5503?
CVE-2014-5503 is classified as a high severity SQL injection vulnerability.
2
How do I fix CVE-2014-5503?
To mitigate CVE-2014-5503, upgrade to Sophos CyberoamOS version 10.6.1 or later.
3
What systems are affected by CVE-2014-5503?
CVE-2014-5503 affects Sophos Cyberoam appliances running CyberoamOS versions prior to 10.6.1.
4
Can CVE-2014-5503 be exploited remotely?
Yes, CVE-2014-5503 can be exploited remotely by attackers to execute arbitrary SQL commands.
5
What is the impact of CVE-2014-5503?
Exploitation of CVE-2014-5503 can lead to unauthorized access and manipulation of the database.