SQL injection vulnerability in OpenVAS Manager before 4.0.6 and 5.x before 5.0.7 allows remote attackers to execute arbitrary SQL commands via the timezone parameter in a modify_schedule OMP command.
References
Link | Resource |
---|---|
http://openwall.com/lists/oss-security/2014/11/30/2 | Mailing List Third Party Advisory |
http://www.openvas.org/OVSA20141128.html | Patch Vendor Advisory |
http://lists.opensuse.org/opensuse-updates/2015-02/msg00039.html | Third Party Advisory |
http://lists.fedoraproject.org/pipermail/package-announce/2015-January/147753.html | Third Party Advisory |
https://www.alienvault.com/forums/discussion/4415/ | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Information
Published : 2014-12-02 17:59
Updated : 2018-10-30 09:27
NVD link : CVE-2014-9220
Mitre link : CVE-2014-9220
JSON object : View
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Products Affected
opensuse
- opensuse
fedoraproject
- fedora
openvas
- openvas_manager