CVE-2014-7176: SQL Injection
Published Nov 4, 2014
·Updated
SQL injection vulnerability in Enalean Tuleap before 7.5.99.4 allows remote authenticated users to execute arbitrary SQL commands via the lobaltxt parameter to plugins/docman.
Affected Software
1 affected component
Enalean Tuleap<=7.5
Event History
Nov 4, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-7176?
CVE-2014-7176 is classified as a medium severity vulnerability due to the potential for remote execution of arbitrary SQL commands.
2
How do I fix CVE-2014-7176?
To fix CVE-2014-7176, upgrade Enalean Tuleap to version 7.5.99.4 or later.
3
Who is affected by CVE-2014-7176?
CVE-2014-7176 affects remote authenticated users of Enalean Tuleap versions prior to 7.5.99.4.
4
What type of vulnerability is CVE-2014-7176?
CVE-2014-7176 is an SQL injection vulnerability that allows execution of arbitrary SQL commands.
5
What parameter is involved in CVE-2014-7176?
The lobal_txt parameter in the plugins/docman is involved in the exploitation of CVE-2014-7176.