CVE-2014-5503
Sophos Cyberoam add_guest_user Blind SQL Injection Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
SQL injection vulnerability in the Guest Login Portal in the Sophos Cyberoam appliances with CyberoamOS before 10.6.1 GA allows remote attackers to execute arbitrary SQL commands via the add_guest_user opcode.
Vulnerabilidad de inyección SQL en el portal de inicio de sesión de huéspedes en los dispositivos Sophos Cyberoam con CyberoamOS anterior a 10.6.1 GA permite a atacantes remotos ejecutar comandos SQL arbitrarios a través del código de operación add_guest_user.
This vulnerability allows remote attackers to execute arbitrary SQL on vulnerable installations of Sophos Cyberoam. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the add_guest_user opcode. The issue lies in the failure to properly sanitize the specified mobile number prior to executing a SQL query. A remote attacker can leverage this vulnerability to disclose credentials and possibly leverage this situation to achieve remote code execution.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-08-28 CVE Reserved
- 2014-10-01 CVE Published
- 2024-08-06 CVE Updated
- 2024-08-19 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.zerodayinitiative.com/advisories/ZDI-14-329 | X_refsource_misc |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://kb.cyberoam.com/default.asp?id=3049 | 2014-10-08 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cyberoam Search vendor "Cyberoam" | Cyberoam Os Search vendor "Cyberoam" for product "Cyberoam Os" | <= 10.4 Search vendor "Cyberoam" for product "Cyberoam Os" and version " <= 10.4" | ga |
Affected
| ||||||
Cyberoam Search vendor "Cyberoam" | Cyberoam Os Search vendor "Cyberoam" for product "Cyberoam Os" | <= 10.6.1 Search vendor "Cyberoam" for product "Cyberoam Os" and version " <= 10.6.1" | rc4 |
Affected
|