Vulnerability Description
SQL injection vulnerability in Resources/System/Templates/Data.aspx in Procentia IntelliPen before 1.1.18.1658 allows remote authenticated users to execute arbitrary SQL commands via the value parameter.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Procentia | Intellipen | <= 1.1.12.1520 |
Related Weaknesses (CWE)
References
- http://seclists.org/fulldisclosure/2014/Mar/103
- http://www.exploit-db.com/exploits/32212
- http://www.securityfocus.com/archive/1/531426/100/0/threaded
- https://www.portcullis-security.com/security-research-and-downloads/security-adv
- http://seclists.org/fulldisclosure/2014/Mar/103
- http://www.exploit-db.com/exploits/32212
- http://www.securityfocus.com/archive/1/531426/100/0/threaded
- https://www.portcullis-security.com/security-research-and-downloads/security-adv
FAQ
What is CVE-2014-2043?
CVE-2014-2043 is a vulnerability with a CVSS score of 6.5 (MEDIUM). SQL injection vulnerability in Resources/System/Templates/Data.aspx in Procentia IntelliPen before 1.1.18.1658 allows remote authenticated users to execute arbitrary SQL commands via the value paramet...
How severe is CVE-2014-2043?
CVE-2014-2043 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-2043?
Check the references section above for vendor advisories and patch information. Affected products include: Procentia Intellipen.