CVE-2014-9258: SQL Injection
Published Dec 19, 2014
·Updated
SQL injection vulnerability in ajax/getDropdownValue.php in GLPI before 0.85.1 allows remote authenticated users to execute arbitrary SQL commands via the condition parameter.
Affected Software
1 affected component
GLPI-PROJECT GLPI<=0.85
Remediation
Event History
Dec 19, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-9258?
CVE-2014-9258 is classified as a high-severity SQL injection vulnerability.
2
How do I fix CVE-2014-9258?
To fix CVE-2014-9258, upgrade GLPI to version 0.85.1 or later.
3
Who is affected by CVE-2014-9258?
Authenticating users of GLPI versions prior to 0.85.1 are affected by CVE-2014-9258.
4
What type of vulnerability is CVE-2014-9258?
CVE-2014-9258 is an SQL injection vulnerability that allows execution of arbitrary SQL commands.
5
When was CVE-2014-9258 published?
CVE-2014-9258 was published in December 2014.