Vulnerability Description
SQL injection vulnerability in mod_accounting.c in the mod_accounting module 0.5 and earlier for Apache allows remote attackers to execute arbitrary SQL commands via a Host header.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Simone Tellini | Mod Accounting | <= 0.5 |
| Apache | Http Server | 1.3 |
Related Weaknesses (CWE)
References
- http://osvdb.org/97588
- http://www.baesystemsdetica.com.au/Research/Advisories/mod_accounting-Blind-SQL-Exploit
- http://osvdb.org/97588
- http://www.baesystemsdetica.com.au/Research/Advisories/mod_accounting-Blind-SQL-Exploit
FAQ
What is CVE-2013-5697?
CVE-2013-5697 is a vulnerability with a CVSS score of 7.5 (HIGH). SQL injection vulnerability in mod_accounting.c in the mod_accounting module 0.5 and earlier for Apache allows remote attackers to execute arbitrary SQL commands via a Host header.
How severe is CVE-2013-5697?
CVE-2013-5697 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-5697?
Check the references section above for vendor advisories and patch information. Affected products include: Simone Tellini Mod Accounting, Apache Http Server.