PT-2014-8885 · Greenbone Networks · Openvas Manager

Publicado

2014-12-03

·

Atualizado

2018-10-30

·

CVE-2014-9220

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions OpenVAS Manager versions prior to 4.0.6 OpenVAS Manager versions 5.x prior to 5.0.7
Description A SQL injection issue allows remote attackers to execute arbitrary SQL commands via the timezone parameter in a modify schedule OMP command.
Recommendations For OpenVAS Manager versions prior to 4.0.6, update to version 4.0.6 or later. For OpenVAS Manager versions 5.x prior to 5.0.7, update to version 5.0.7 or later.

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-9220
MGASA-2015-0001

Produtos afetados

Openvas Manager