CVE-2018-12295: SQL Injection
Published May 13, 2019
·Updated
SQL injection in folderViewSpecific.psp in Seagate NAS OS version 4.3.15.1 allows attackers to execute arbitrary SQL commands via the dirId URL parameter.
Affected Software
1 affected component
Seagate NAS OS=4.3.15.1
Event History
May 13, 2019
CVE Published
via MITRE·12:31 PM
Data Sourced
via MITRE·12:31 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-12295?
CVE-2018-12295 is classified as a high-severity vulnerability due to the potential for remote SQL injection.
2
How do I fix CVE-2018-12295?
To fix CVE-2018-12295, upgrade Seagate NAS OS to a version later than 4.3.15.1 that addresses the SQL injection flaw.
3
What are the risks associated with CVE-2018-12295?
The risks associated with CVE-2018-12295 include unauthorized data access and potential data manipulation through SQL injection.
4
Is my system vulnerable to CVE-2018-12295?
If you are running Seagate NAS OS version 4.3.15.1, your system is vulnerable to CVE-2018-12295.
5
What components are affected by CVE-2018-12295?
CVE-2018-12295 affects the folderViewSpecific.psp component in Seagate NAS OS version 4.3.15.1.