CVE-2016-8025: SQL Injection
Published Mar 14, 2017
·Updated
SQL injection vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote authenticated users to obtain product information via a crafted HTTP request parameter.
Affected Software
1 affected component
McAfee Virusscan Enterprise Linux<=2.0.3
Event History
Mar 14, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-8025?
CVE-2016-8025 has a severity score that indicates it is a critical SQL injection vulnerability.
2
How do I fix CVE-2016-8025?
To fix CVE-2016-8025, upgrade Intel Security VirusScan Enterprise Linux to version 2.0.4 or later.
3
Who is affected by CVE-2016-8025?
CVE-2016-8025 affects remote authenticated users of Intel Security VirusScan Enterprise Linux version 2.0.3 and earlier.
4
What can an attacker do with CVE-2016-8025?
An attacker exploiting CVE-2016-8025 can obtain sensitive product information through specially crafted HTTP request parameters.
5
Is CVE-2016-8025 easy to exploit?
Yes, CVE-2016-8025 can be exploited with minimal effort if the attacker has authenticated access.