CVE-2011-0467
Summary
| CVE | CVE-2011-0467 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-06-07 21:29:00 UTC |
| Updated | 2023-11-07 02:06:00 UTC |
| Description | A vulnerability in the listing of available software of SUSE Studio Onsite, SUSE Studio Onsite 1.1 Appliance allows authenticated users to execute arbitrary SQL statements via SQL injection. Affected releases are SUSE Studio Onsite: versions prior to 1.0.3-0.18.1, SUSE Studio Onsite 1.1 Appliance: versions prior to 1.1.2-0.25.1. |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Suse | Studio Onsite | All | All | All | All |
| Application | Suse | Studio Onsite | All | All | All | All |
| Application | Suse | Studio Onsite Appliance | All | All | All | All |
| Application | Suse | Studio Onsite Appliance | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2011-0467 | SUSE | CONFIRM | www.suse.com | Vendor Advisory |
| Bug 675039 – VUL-0: CVE-2011-0467: Studio: SQL injections | CONFIRM | bugzilla.suse.com | Exploit, Issue Tracking, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Matthias Weckbecker of SUSE
There are currently no legacy QID mappings associated with this CVE.