CVE-2016-7803: SQL Injection
Published Jun 9, 2017
·Updated
SQL injection vulnerability in the Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to execute arbitrary SQL commands via "MultiReport" function.
Affected Software
27 affected components
Cybozu Garoon=3.0.0
Cybozu Garoon=3.0.1
Cybozu Garoon=3.0.2
Cybozu Garoon=3.0.3
Cybozu Garoon=3.1.0
Cybozu Garoon=3.1.1
Cybozu Garoon=3.1.2
Cybozu Garoon=3.1.3
Cybozu Garoon=3.5.0
Cybozu Garoon=3.5.1
Cybozu Garoon=3.5.2
Cybozu Garoon=3.5.3
Cybozu Garoon=3.5.4
Cybozu Garoon=3.5.5
Cybozu Garoon=3.7.0
Cybozu Garoon=3.7.1
Cybozu Garoon=3.7.2
Cybozu Garoon=3.7.3
Cybozu Garoon=3.7.4
Cybozu Garoon=3.7.5
Cybozu Garoon=4.0.0
Cybozu Garoon=4.0.1
Cybozu Garoon=4.0.2
Cybozu Garoon=4.0.3
Cybozu Garoon=4.2.0
Cybozu Garoon=4.2.1
Cybozu Garoon=4.2.2
Event History
Jun 9, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-7803?
CVE-2016-7803 is classified as a high severity SQL injection vulnerability.
2
How do I fix CVE-2016-7803?
To fix CVE-2016-7803, update your Cybozu Garoon installation to version 4.2.3 or later which addresses this vulnerability.
3
Which versions of Cybozu Garoon are affected by CVE-2016-7803?
CVE-2016-7803 affects Cybozu Garoon versions 3.0.0 to 4.2.2.
4
What type of vulnerability is CVE-2016-7803?
CVE-2016-7803 is an SQL injection vulnerability that allows attackers to execute arbitrary SQL commands.
5
Who can exploit CVE-2016-7803?
CVE-2016-7803 can be exploited by remote authenticated attackers through the MultiReport function.