Lucene search

K
nvd[email protected]NVD:CVE-2014-2351
HistoryMay 20, 2014 - 11:13 a.m.

CVE-2014-2351

2014-05-2011:13:37
CWE-89
web.nvd.nist.gov
1

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.2

Confidence

Low

EPSS

0.007

Percentile

80.5%

SQL injection vulnerability in the LiveData service in CSWorks before 2.5.5233.0 allows remote attackers to execute arbitrary SQL commands via vectors related to pathnames contained in web API requests.

Affected configurations

Nvd
Node
controlsystemworkscsworksRange2.5.5050.0
OR
controlsystemworkscsworksMatch1.0.601.0
OR
controlsystemworkscsworksMatch1.0.612.0
OR
controlsystemworkscsworksMatch1.0.623.0
OR
controlsystemworkscsworksMatch1.0.720.0
OR
controlsystemworkscsworksMatch1.0.801.0
OR
controlsystemworkscsworksMatch1.0.813.0
OR
controlsystemworkscsworksMatch1.0.901.0
OR
controlsystemworkscsworksMatch1.0.3540.0
OR
controlsystemworkscsworksMatch1.0.3560.0
OR
controlsystemworkscsworksMatch1.0.3580.0
OR
controlsystemworkscsworksMatch1.1.3600.0
OR
controlsystemworkscsworksMatch1.1.3674.0
OR
controlsystemworkscsworksMatch1.1.3700.0
OR
controlsystemworkscsworksMatch1.2.3730.0
OR
controlsystemworkscsworksMatch1.2.3800.0
OR
controlsystemworkscsworksMatch1.4.3820.0
OR
controlsystemworkscsworksMatch1.4.3830.0
OR
controlsystemworkscsworksMatch1.4.3850.0
OR
controlsystemworkscsworksMatch1.4.3860.0
OR
controlsystemworkscsworksMatch1.4.3880.0
OR
controlsystemworkscsworksMatch1.4.3900.0
OR
controlsystemworkscsworksMatch1.4.4000.0
OR
controlsystemworkscsworksMatch1.7.4050.0
OR
controlsystemworkscsworksMatch1.7.5000.0
OR
controlsystemworkscsworksMatch2.0.4115.0
OR
controlsystemworkscsworksMatch2.0.4115.1
OR
controlsystemworkscsworksMatch2.1.4386.0
OR
controlsystemworkscsworksMatch2.1.4560.0
OR
controlsystemworkscsworksMatch2.5.4770.0
OR
controlsystemworkscsworksMatch2.5.4770.1
OR
controlsystemworkscsworksMatch2.5.4912.0
VendorProductVersionCPE
controlsystemworkscsworks*cpe:2.3:a:controlsystemworks:csworks:*:*:*:*:*:*:*:*
controlsystemworkscsworks1.0.601.0cpe:2.3:a:controlsystemworks:csworks:1.0.601.0:*:*:*:*:*:*:*
controlsystemworkscsworks1.0.612.0cpe:2.3:a:controlsystemworks:csworks:1.0.612.0:*:*:*:*:*:*:*
controlsystemworkscsworks1.0.623.0cpe:2.3:a:controlsystemworks:csworks:1.0.623.0:*:*:*:*:*:*:*
controlsystemworkscsworks1.0.720.0cpe:2.3:a:controlsystemworks:csworks:1.0.720.0:*:*:*:*:*:*:*
controlsystemworkscsworks1.0.801.0cpe:2.3:a:controlsystemworks:csworks:1.0.801.0:*:*:*:*:*:*:*
controlsystemworkscsworks1.0.813.0cpe:2.3:a:controlsystemworks:csworks:1.0.813.0:*:*:*:*:*:*:*
controlsystemworkscsworks1.0.901.0cpe:2.3:a:controlsystemworks:csworks:1.0.901.0:*:*:*:*:*:*:*
controlsystemworkscsworks1.0.3540.0cpe:2.3:a:controlsystemworks:csworks:1.0.3540.0:*:*:*:*:*:*:*
controlsystemworkscsworks1.0.3560.0cpe:2.3:a:controlsystemworks:csworks:1.0.3560.0:*:*:*:*:*:*:*
Rows per page:
1-10 of 321

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.2

Confidence

Low

EPSS

0.007

Percentile

80.5%

Related for NVD:CVE-2014-2351