Cisco Identity Services Engine Web Framework CVE-2014-3275 SQL Injection Vulnerability
BID:67555
Info
Cisco Identity Services Engine Web Framework CVE-2014-3275 SQL Injection Vulnerability
| Bugtraq ID: | 67555 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-3275 |
| Remote: | Yes |
| Local: | No |
| Published: | May 21 2014 12:00AM |
| Updated: | May 21 2014 12:00AM |
| Credit: | Cisco |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Cisco Identity Services Engine Web Framework CVE-2014-3275 SQL Injection Vulnerability
Cisco Identity Services Engine is prone to an SQL-injection vulnerability.
A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
This issue is being tracked by Cisco Bug ID CSCul21337.
Cisco Identity Services Engine is prone to an SQL-injection vulnerability.
A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
This issue is being tracked by Cisco Bug ID CSCul21337.
Exploit / POC
Cisco Identity Services Engine Web Framework CVE-2014-3275 SQL Injection Vulnerability
Attacker can exploit this issue using a browser.
Attacker can exploit this issue using a browser.
Solution / Fix
Cisco Identity Services Engine Web Framework CVE-2014-3275 SQL Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Cisco Identity Services Engine Web Framework CVE-2014-3275 SQL Injection Vulnerability
References:
References:
- Cisco Homepage (Cisco)