Description
Multiple SQL injection vulnerabilities in interface PHP scripts in the Manager component in Symantec Endpoint Protection (SEP) before 12.1.6 allow remote authenticated users to execute arbitrary SQL commands by leveraging the Limited Administrator role.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2014-9054 | Multiple SQL injection vulnerabilities in interface PHP scripts in the Manager component in Symantec Endpoint Protection (SEP) before 12.1.6 allow remote authenticated users to execute arbitrary SQL commands by leveraging the Limited Administrator role. |
References
History
No history.
Status: PUBLISHED
Assigner: symantec
Published:
Updated: 2024-08-06T13:40:24.717Z
Reserved: 2014-12-03T00:00:00.000Z
Link: CVE-2014-9229
No data.
Status : Modified
Published: 2015-09-20T20:59:02.917
Modified: 2026-06-17T00:17:57.850
Link: CVE-2014-9229
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
EUVD