First published: Thu Nov 20 2014(Updated: )
SQL injection vulnerability in Maarch LetterBox 2.8 allows remote attackers to execute arbitrary SQL commands via the UserId cookie.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Maarch | =2.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8995 is considered a high severity vulnerability due to its potential for arbitrary SQL command execution.
Fixing CVE-2014-8995 requires upgrading to a patched version of Maarch LetterBox or implementing input validation to sanitize UserId cookie data.
CVE-2014-8995 affects users of Maarch LetterBox version 2.8.
CVE-2014-8995 is classified as an SQL injection vulnerability.
Attackers exploiting CVE-2014-8995 can execute arbitrary SQL commands that may compromise the database.