SQL injection vulnerability in the LiveData service in CSWorks before 2.5.5233.0 allows remote attackers to execute arbitrary SQL commands via vectors related to pathnames contained in web API requests.
References
| Link | Resource |
|---|---|
| http://www.controlsystemworks.com/blogengine/post/2014/05/08/Important-CSWorks-security-release-2552330 | Vendor Advisory |
| http://ics-cert.us-cert.gov/advisories/ICSA-14-135-01 | US Government Resource |
| http://www.securityfocus.com/bid/67427 |
Configurations
Configuration 1 (hide)
|
Information
Published : 2014-05-20 04:13
Updated : 2015-10-08 07:47
NVD link : CVE-2014-2351
Mitre link : CVE-2014-2351
JSON object : View
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Products Affected
controlsystemworks
- csworks


