SQL injection vulnerability in the LiveData service in CSWorks before 2.5.5233.0 allows remote attackers to execute arbitrary SQL commands via vectors related to pathnames contained in web API requests.
Advisories
Source ID Title
EUVD EUVD EUVD-2014-2388 SQL injection vulnerability in the LiveData service in CSWorks before 2.5.5233.0 allows remote attackers to execute arbitrary SQL commands via vectors related to pathnames contained in web API requests.
Fixes

Solution

CSWorks has addressed this vulnerability in the updated version of CSWorks, Version 2.5.5233.0. The updated version of CSWorks is available at:  http://www.controlsystemworks.com/DownloadDescription.aspx  . For additional mitigation and installation information, please review CSWorks’ security release at the following location:  http://www.controlsystemworks.com/blogengine/post/2014/05/08/Important-CSWorks-security-release-2552330


Workaround

No workaround given by the vendor.

History

Fri, 03 Oct 2025 16:30:00 +0000

Type Values Removed Values Added
Title CSWorks SQL Injection
References

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-10-03T16:17:47.843Z

Reserved: 2014-03-13T00:00:00

Link: CVE-2014-2351

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2014-05-20T11:13:37.873

Modified: 2025-10-03T17:15:44.887

Link: CVE-2014-2351

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.