PT-2014-3400 · F Secure+2 · F-Secure Anti-Virus For Windows Servers+7
Andrea Micalizzi
+1
·
Publicado
2014-04-18
·
Atualizado
2014-04-21
·
CVE-2013-7369
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
F-Secure Anti-Virus for Microsoft Exchange Server versions prior to HF02
F-Secure Anti-Virus for Windows Servers 9.00 versions prior to HF09
F-Secure Anti-Virus for Citrix Servers 9.00 versions prior to HF09
F-Secure Email and Server Security 9.20 versions prior to HF01
F-Secure Server Security 9.20 versions prior to HF01
Description
The issue allows remote attackers to execute arbitrary SQL commands via unknown vectors, related to the
GetCommand function. This is a result of a SQL injection vulnerability in an unspecified DLL in the FSDBCom ActiveX control.Recommendations
For F-Secure Anti-Virus for Microsoft Exchange Server versions prior to HF02, update to a version that includes HF02 or later.
For F-Secure Anti-Virus for Windows Servers 9.00 versions prior to HF09, update to a version that includes HF09 or later.
For F-Secure Anti-Virus for Citrix Servers 9.00 versions prior to HF09, update to a version that includes HF09 or later.
For F-Secure Email and Server Security 9.20 versions prior to HF01, update to a version that includes HF01 or later.
For F-Secure Server Security 9.20 versions prior to HF01, update to a version that includes HF01 or later.
Correção
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Citrix Servers
F-Secure Anti-Virus For Citrix Servers
F-Secure Anti-Virus For Microsoft Exchange
F-Secure Anti-Virus For Windows Servers
F-Secure Email/Server Security
F-Secure Server Security
Exchange Server
Windows Server