CVE-2014-6293: SQL Injection
SQL injection vulnerability in the Statistics (kestats) extension before 1.1.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, as exploited in the wild in February 2014.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6293?
CVE-2014-6293 is considered a critical SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands.
How do I fix CVE-2014-6293?
To fix CVE-2014-6293, upgrade the TYPO3 Statistics (ke_stats) extension to version 1.1.2 or later.
What versions of TYPO3 are affected by CVE-2014-6293?
CVE-2014-6293 affects TYPO3 installations using the Statistics (ke_stats) extension version 1.1.1 and earlier.
How can an attacker exploit CVE-2014-6293?
An attacker can exploit CVE-2014-6293 by using unspecified vectors within the Statistics extension to inject malicious SQL commands.
Is CVE-2014-6293 actively exploited?
Yes, CVE-2014-6293 was actively exploited in the wild in February 2014.